Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 45/1469
8.8
CVE-2026-74952

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 15

8.8
CVE-2026-74950

Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thu

8.8
CVE-2026-74949

Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fir

8.8
CVE-2026-74947

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Fire

8.8
CVE-2026-74946

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was

8.8
CVE-2026-74942

Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 1

8.8
CVE-2026-74941

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 14

8.8
CVE-2026-74939

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

8.8
CVE-2026-74937

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb

8.8
CVE-2026-74935

Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

7.5
CVE-2026-74934

Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 11

8.7
CVE-2026-75855

ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database an

8.8
CVE-2026-75853

ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (S

7.1
CVE-2026-75846

ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTI

7.1
CVE-2026-75844

ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where

7.7
CVE-2026-75842

ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that

7.5
CVE-2026-75840

ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforce

8.8
CVE-2026-75836

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce t

7.6
CVE-2026-75831

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through t

7.1
CVE-2026-75830

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability

8.1
CVE-2026-75829

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers wit

8.7
CVE-2026-75828

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quote

8.8
CVE-2026-75827

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation

7.5
CVE-2026-74906

SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints tha

7.1
CVE-2026-74905

SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/u

7.5
CVE-2026-74904

SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (incl

8.6
CVE-2026-74902

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to esca

7.5
CVE-2026-15585

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer I

8.1
CVE-2026-15371

Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and form

7.2
CVE-2026-75091

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-

7.5
CVE-2026-11801

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

7.3
CVE-2026-75089

A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown fun

7.3
CVE-2026-75080

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects s

7.3
CVE-2026-75079

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unkno

7.8
CVE-2026-67961

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke

8.3
CVE-2026-9816

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields

7.1
CVE-2026-69148

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior t

7.5
CVE-2026-67918

Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via

8.8
CVE-2026-65346

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, m

7.5
CVE-2026-65343

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.

8.6
CVE-2026-56677

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/o

8.0
CVE-2026-45790

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC

8.8
CVE-2026-43794

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10

7.5
CVE-2026-75482

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths t

8.8
CVE-2026-75481

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service acco

7.5
CVE-2026-75479

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows un

7.5
CVE-2026-75111

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthe

7.1
CVE-2026-75109

Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authe

7.5
CVE-2026-75105

phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issu

8.8
CVE-2026-75103

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticate

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started