Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 16/1469
7.8
CVE-2026-61419

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attac

7.5
CVE-2026-75371

An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-

8.1
CVE-2026-71506

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that al

7.1
CVE-2026-71505

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site accou

8.1
CVE-2026-71504

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers wi

8.7
CVE-2026-40877

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in th

8.9
CVE-2026-30864

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scrip

8.1
CVE-2025-26238

In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

8.1
CVE-2025-26237

D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b

8.5
CVE-2026-76838

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backen

8.8
CVE-2026-76836

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission gu

8.8
CVE-2026-76073

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label

7.4
CVE-2026-76072

The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende

7.2
CVE-2026-71943

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerabili

7.2
CVE-2026-71942

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerab

7.2
CVE-2026-71941

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerabil

7.2
CVE-2026-71940

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function.

7.2
CVE-2026-71939

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. T

7.2
CVE-2026-71938

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnera

7.2
CVE-2026-71937

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vu

7.2
CVE-2026-71936

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability

7.2
CVE-2026-71935

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnera

7.2
CVE-2026-71934

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability

7.2
CVE-2026-71931

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerab

7.2
CVE-2026-71930

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability

7.2
CVE-2026-71929

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerabi

7.2
CVE-2026-71928

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerabil

7.2
CVE-2026-71927

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerabili

7.2
CVE-2026-71926

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerabili

7.2
CVE-2026-71925

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerabili

7.2
CVE-2026-71924

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability

7.2
CVE-2026-71923

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerabilit

7.5
CVE-2026-71922

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cg

7.2
CVE-2026-71919

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerabili

7.2
CVE-2026-71918

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulne

7.2
CVE-2026-71917

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerabili

7.2
CVE-2026-71916

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerab

7.2
CVE-2026-71915

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerabil

7.2
CVE-2026-71913

Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vuln

7.2
CVE-2026-71912

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is

7.2
CVE-2026-71911

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is cau

7.2
CVE-2026-71910

Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability

7.2
CVE-2026-71909

Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability

7.2
CVE-2026-71908

Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vul

7.2
CVE-2026-71907

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability i

7.2
CVE-2026-71906

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is c

7.2
CVE-2026-71905

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerabil

7.2
CVE-2026-71904

Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerabi

7.0
CVE-2026-78465

A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plu

7.5
CVE-2026-66908

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started