Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 21/1469
8.8
CVE-2026-33240

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS)

8.8
CVE-2026-31936

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object informat

8.7
CVE-2026-77811

Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated

7.1
CVE-2026-77219

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak he

7.5
CVE-2026-76905

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in o

7.8
CVE-2026-68508

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves

8.1
CVE-2026-64679

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 un

7.5
CVE-2026-63421

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core

8.2
CVE-2026-63135

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Refe

8.8
CVE-2026-62316

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/

8.2
CVE-2026-61824

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:im

7.7
CVE-2026-54457

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and e

8.8
CVE-2026-50538

LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or ma

8.0
CVE-2026-31880

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)

8.0
CVE-2026-31803

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting

8.0
CVE-2026-30890

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)

7.1
CVE-2026-30865

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)

8.0
CVE-2026-30826

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)

7.4
CVE-2026-62960

Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bun

7.5
CVE-2026-30866

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensit

7.3
CVE-2026-30819

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS)

7.5
CVE-2026-27490

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being

7.5
CVE-2026-27462

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/inval

7.5
CVE-2026-63462

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation e

8.2
CVE-2026-54682

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting

7.8
CVE-2026-54071

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py d

7.3
CVE-2026-77236

Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to

7.3
CVE-2026-77235

Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local

8.8
CVE-2026-77234

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to exec

7.5
CVE-2026-71862

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and

8.8
CVE-2026-62677

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authe

7.1
CVE-2026-62676

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shar

8.8
CVE-2026-62675

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipar

7.5
CVE-2026-55241

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and

7.8
CVE-2026-41451

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substi

7.8
CVE-2026-41450

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_co

7.8
CVE-2026-41449

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_comman

7.8
CVE-2026-74583

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on

7.8
CVE-2026-74582

In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring

8.8
CVE-2026-74580

In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring reco

8.1
CVE-2026-39909

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows u

7.3
CVE-2026-75933

Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Inject

8.6
CVE-2026-75932

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authent

7.5
CVE-2026-54789

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that impl

7.1
CVE-2026-49114

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_da

8.5
CVE-2026-22681

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege att

7.5
CVE-2026-77815

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but

7.5
CVE-2026-77814

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.starts

7.5
CVE-2026-75501

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote a

7.7
CVE-2026-55622

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started