Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 329/1469
7.8
CVE-2026-34588

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the

7.1
CVE-2026-34379

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the

7.2
CVE-2026-34217

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sand

7.5
CVE-2026-34211

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion

7.5
CVE-2026-34148

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8,

8.6
CVE-2026-33752

curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges,

7.8
CVE-2026-21382

Memory Corruption when handling power management requests with improperly sized input/output buffers.

7.6
CVE-2026-21381

Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware

7.8
CVE-2026-21380

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

7.8
CVE-2026-21378

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor

7.8
CVE-2026-21376

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor

7.8
CVE-2026-21375

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

7.8
CVE-2026-21374

Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio

7.8
CVE-2026-21373

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

7.8
CVE-2026-21372

Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.

7.8
CVE-2026-21371

Memory Corruption when retrieving output buffer with insufficient size validation.

7.6
CVE-2026-21367

Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.

7.1
CVE-2025-47400

Cryptographic issue while copying data to a destination buffer without validating its size.

8.8
CVE-2025-47392

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

7.8
CVE-2025-47391

Memory corruption while processing a frame request from user.

7.8
CVE-2025-47390

Memory corruption while preprocessing IOCTL request in JPEG driver.

7.8
CVE-2025-47389

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

7.8
CVE-2024-14032

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that

7.3
CVE-2026-5663

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEn

8.5
CVE-2026-34885

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi

7.5
CVE-2026-33540

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mod

8.8
CVE-2026-33510

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been disco

7.2
CVE-2026-29047

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user

8.1
CVE-2026-26263

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based bli

7.5
CVE-2026-26027

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store

7.2
CVE-2026-25932

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user c

7.5
CVE-2026-30078

OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. Fo

8.8
CVE-2026-3524

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in Serv

7.3
CVE-2026-5648

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /u

7.3
CVE-2026-5646

A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown f

7.3
CVE-2026-5645

A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown func

7.3
CVE-2026-5642

A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th

7.3
CVE-2026-5637

A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown co

7.3
CVE-2026-5634

A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown fun

7.3
CVE-2026-5633

A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the compone

8.8
CVE-2026-31409

In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding reques

8.8
CVE-2026-31408

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix use-after-free in sco_recv_fram

7.1
CVE-2026-31407

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy va

7.8
CVE-2026-31406

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix work re-schedule after cancel in xfrm_nat

7.3
CVE-2026-5632

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component H

7.3
CVE-2026-5631

A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data

8.8
CVE-2026-5629

A vulnerability was detected in Belkin F9K1015 1.00.10. The affected element is the function formSetFirewall of the file

8.8
CVE-2026-5628

A security vulnerability has been detected in Belkin F9K1015 1.00.10. Impacted is the function formSetSystemSettings of

7.3
CVE-2026-5616

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the

8.8
CVE-2026-5614

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /gof

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started