Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 59/1469
8.1
CVE-2026-17206

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

7.5
CVE-2026-17199

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource alloca

8.1
CVE-2026-17069

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

8.1
CVE-2026-17045

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access s

8.8
CVE-2026-17029

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

7.5
CVE-2026-17004

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.

8.8
CVE-2026-16987

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the

7.5
CVE-2026-16982

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.

8.8
CVE-2026-16975

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based b

8.5
CVE-2026-16967

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects d

7.6
CVE-2026-16961

IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, wh

8.5
CVE-2026-16908

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary object

7.8
CVE-2026-16898

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due t

7.1
CVE-2026-16896

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a

7.5
CVE-2026-16887

IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

8.1
CVE-2026-16868

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized

8.1
CVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenti

8.6
CVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive

8.8
CVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improp

8.8
CVE-2026-16674

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted s

7.3
CVE-2026-14875

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when install

7.5
CVE-2026-13460

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code

7.1
CVE-2026-13365

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to e

8.2
CVE-2026-73650

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version

8.1
CVE-2026-73482

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The admin

8.6
CVE-2026-72777

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint

7.8
CVE-2026-18071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege manageme

8.2
CVE-2026-17220

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metada

8.1
CVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of

7.5
CVE-2026-73643

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponenti

7.5
CVE-2026-73568

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming()

7.5
CVE-2026-73566

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses

7.5
CVE-2026-73561

Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSoc

8.1
CVE-2026-72741

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticat

8.8
CVE-2026-18428

A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenti

7.5
CVE-2024-58374

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows r

7.5
CVE-2019-25765

ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attack

7.1
CVE-2026-73266

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exp

7.5
CVE-2026-59765

SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

8.8
CVE-2026-59109

SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic in

8.1
CVE-2026-58439

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

7.5
CVE-2026-58438

Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot

7.1
CVE-2026-58437

Repository Visibility Manipulation via Git Push Options

7.5
CVE-2026-58436

ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

7.5
CVE-2026-58434

Private Repository Metadata Remains Accessible After Access Revocation

7.5
CVE-2026-58427

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

7.5
CVE-2026-58417

REST API exposes organization membership of private organizations to public

7.1
CVE-2026-58416

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

7.7
CVE-2026-58314

Two SSRF findings in Gitea 1.26.2

8.5
CVE-2026-57894

Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfil

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started