Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 42/1469
7.8
CVE-2026-60414

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th

7.8
CVE-2026-60413

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th

7.8
CVE-2026-60412

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th

7.5
CVE-2026-60393

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme

7.8
CVE-2026-60392

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export

7.5
CVE-2026-60391

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

7.8
CVE-2026-55426

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfa

7.2
CVE-2026-54348

Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib

8.7
CVE-2026-54347

Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Ap

8.1
CVE-2026-52793

Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/Fr

7.3
CVE-2026-15571

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity

7.5
CVE-2026-75936

Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 migh

7.5
CVE-2026-75935

Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actor

7.5
CVE-2026-71676

Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS d

7.5
CVE-2026-71675

An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in

7.3
CVE-2026-71417

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to

8.1
CVE-2026-71308

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted r

7.7
CVE-2026-71307

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only

7.7
CVE-2026-71303

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when a

7.4
CVE-2026-70666

Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/

7.3
CVE-2026-59915

Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A

7.5
CVE-2026-52829

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically termi

7.5
CVE-2026-52481

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via t

8.2
CVE-2026-47719

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and

7.5
CVE-2026-47629

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validatio

7.5
CVE-2026-47628

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resourc

7.1
CVE-2026-24185

NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while

7.5
CVE-2026-24184

NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an una

7.8
CVE-2026-24183

NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use imp

8.1
CVE-2025-9210

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows

7.1
CVE-2026-74038

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause

7.8
CVE-2026-71551

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.1

8.8
CVE-2026-67920

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.Migration

7.8
CVE-2026-67846

Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect priv

8.1
CVE-2026-67262

Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit t

7.9
CVE-2026-54552

sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on

8.1
CVE-2026-50143

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation

8.8
CVE-2026-48508

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/aut

8.1
CVE-2026-44472

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats

7.3
CVE-2026-32657

Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, D

8.7
CVE-2026-75924

A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive p

7.5
CVE-2026-75897

Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload i

8.1
CVE-2026-70415

Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthentic

8.2
CVE-2026-66783

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vuln

7.8
CVE-2026-66782

A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service a

8.8
CVE-2026-61574

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list r

7.5
CVE-2026-50578

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic

7.4
CVE-2026-50577

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic

8.8
CVE-2026-49228

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

8.3
CVE-2026-49225

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started