Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 2/1469
7.5
CVE-2026-81517

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough r

7.7
CVE-2026-81490

A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling

7.5
CVE-2026-77078

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially c

7.5
CVE-2026-77037

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is abort

8.2
CVE-2026-18904

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthori

7.5
CVE-2026-18899

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.

8.2
CVE-2026-18891

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive info

8.8
CVE-2026-18729

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to impro

7.5
CVE-2026-17203

IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive informatio

7.0
CVE-2026-16821

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format s

8.1
CVE-2026-82291

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cros

7.4
CVE-2026-82289

Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab.,

7.5
CVE-2026-82288

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint

8.1
CVE-2026-82287

Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions b

8.6
CVE-2026-82286

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthent

8.2
CVE-2026-82285

bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/call

8.1
CVE-2026-82284

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id

8.1
CVE-2026-82283

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users t

8.0
CVE-2026-82282

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to acce

7.4
CVE-2026-82281

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and

7.1
CVE-2026-82280

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt

8.1
CVE-2026-82279

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team membe

8.8
CVE-2026-82278

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authen

7.5
CVE-2026-82275

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file acc

7.5
CVE-2026-82270

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lac

8.1
CVE-2026-82269

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middl

7.5
CVE-2026-82268

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats

8.3
CVE-2026-82021

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remot

8.8
CVE-2026-81849

Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before

8.0
CVE-2026-77586

In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted

8.0
CVE-2026-75486

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .verv

7.5
CVE-2026-75124

PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the w

7.2
CVE-2026-75123

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b

7.2
CVE-2026-75122

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b

7.2
CVE-2026-75121

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b

8.8
CVE-2026-72984

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

8.1
CVE-2026-56100

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows a

7.5
CVE-2026-55584

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control

7.5
CVE-2026-55552

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated r

8.8
CVE-2026-55521

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPac

8.8
CVE-2026-55485

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0,

7.5
CVE-2026-55484

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.

7.5
CVE-2026-55215

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

8.5
CVE-2026-55108

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.

7.1
CVE-2026-55066

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v

8.1
CVE-2026-55065

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:projec

7.5
CVE-2026-54788

dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/

8.5
CVE-2026-82227

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

7.5
CVE-2026-81767

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

7.1
CVE-2026-81760

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started