Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 407/1469
7.5
CVE-2026-20652

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,

7.5
CVE-2026-20650

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS

7.5
CVE-2026-20649

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe

7.1
CVE-2026-20641

A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iP

7.1
CVE-2026-20628

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS

7.8
CVE-2026-20626

This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, ma

7.7
CVE-2026-20620

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, m

7.0
CVE-2026-20617

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequ

8.8
CVE-2026-20616

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 1

7.8
CVE-2026-20615

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Seq

7.8
CVE-2026-20614

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma

7.8
CVE-2026-20611

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS

7.8
CVE-2026-20610

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able

7.1
CVE-2026-20606

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3

7.5
CVE-2026-1669

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supp

7.5
CVE-2025-46290

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad

7.5
CVE-2026-26029

sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability ex

8.8
CVE-2024-50619

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to es

7.5
CVE-2024-50617

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to

7.0
CVE-2026-26158

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction di

7.0
CVE-2026-26157

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craf

7.6
CVE-2026-26010

OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines

7.1
CVE-2026-25999

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper acces

7.5
CVE-2026-25990

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a

8.4
CVE-2026-25924

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulner

8.7
CVE-2026-25759

Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnera

7.6
CVE-2025-64487

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability e

8.8
CVE-2024-50620

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon

7.5
CVE-2020-37215

MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the applica

7.5
CVE-2020-37214

Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by man

7.5
CVE-2020-37213

TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sendi

7.5
CVE-2020-37212

SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to c

7.5
CVE-2020-37211

SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a larg

7.5
CVE-2020-37210

SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the

7.5
CVE-2020-37209

SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to

7.5
CVE-2020-37208

SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to cr

7.5
CVE-2020-37207

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to

7.5
CVE-2020-37206

ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an

7.5
CVE-2020-37205

RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflo

7.5
CVE-2020-37204

RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to cr

7.5
CVE-2020-37203

Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the applicatio

7.5
CVE-2020-37202

NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by suppl

7.5
CVE-2020-37201

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to

7.5
CVE-2020-37200

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to

7.5
CVE-2020-37199

NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to cras

7.5
CVE-2020-37198

Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability that allows attackers to crash the application by

7.5
CVE-2020-37197

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the applicati

7.5
CVE-2020-37196

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the applicati

7.5
CVE-2020-37195

BlueAuditor 1.7.2.0 contains a denial of service vulnerability in the registration name input field that allows attacker

7.5
CVE-2020-37194

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by s

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started