Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 63/1469
8.2
CVE-2026-18945

The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confir

7.5
CVE-2026-13610

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registrat

7.5
CVE-2026-0301

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an u

8.8
CVE-2026-49473

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization in

7.5
CVE-2026-47717

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/pro

7.7
CVE-2026-73498

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, co

7.4
CVE-2026-73495

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42

7.5
CVE-2026-73493

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42,

8.5
CVE-2026-71473

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed clu

7.5
CVE-2026-71469

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random b

7.8
CVE-2026-19003

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setu

8.2
CVE-2026-17485

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information

8.4
CVE-2026-10534

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

7.5
CVE-2026-73418

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the

7.5
CVE-2026-65370

ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. Th

7.5
CVE-2026-19654

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input se

8.1
CVE-2026-19004

An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output pa

8.1
CVE-2026-19002

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can resu

7.8
CVE-2026-16695

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to imp

8.5
CVE-2026-16033

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creat

7.7
CVE-2026-14866

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to

8.8
CVE-2026-13622

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-hand

7.3
CVE-2026-13476

IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands wit

8.3
CVE-2026-13433

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when c

7.8
CVE-2026-13367

IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root

8.8
CVE-2026-13105

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a

7.8
CVE-2026-13094

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when install

8.2
CVE-2026-10543

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted

7.5
CVE-2026-73406

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_EN

8.7
CVE-2026-73332

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privile

7.1
CVE-2026-73331

CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post cr

8.7
CVE-2026-73329

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execu

7.6
CVE-2026-73326

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access a

8.2
CVE-2026-73303

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a cli

8.0
CVE-2026-72809

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth f

8.0
CVE-2026-72807

SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that

8.6
CVE-2026-72804

SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing a

7.5
CVE-2026-72801

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthen

8.6
CVE-2026-72798

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymou

8.6
CVE-2026-72795

SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and ge

8.6
CVE-2026-72794

siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthen

8.6
CVE-2026-72793

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing

8.6
CVE-2026-72789

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly access

7.4
CVE-2026-67579

Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter

7.8
CVE-2026-59917

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerab

7.8
CVE-2026-59916

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerab

7.8
CVE-2026-59914

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoo

7.8
CVE-2026-46731

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoo

8.5
CVE-2026-19228

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u

8.9
CVE-2026-18099

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to imprope

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started