Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 66/1469
7.8
CVE-2026-68445

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming w

7.8
CVE-2026-68442

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split

7.8
CVE-2026-68440

In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix heap overflow when reading module E

8.6
CVE-2026-68433

In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front le

8.8
CVE-2026-68432

In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns fo

7.5
CVE-2026-73249

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{librar

8.6
CVE-2026-73247

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/cor

7.5
CVE-2026-73246

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest

7.4
CVE-2026-67558

The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match aga

8.8
CVE-2026-66875

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range

8.8
CVE-2026-5917

libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shel

7.5
CVE-2026-29036

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointe

8.8
CVE-2026-19560

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code ins

8.8
CVE-2026-19559

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code insi

7.5
CVE-2026-19558

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to instal

8.3
CVE-2026-19557

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised

8.8
CVE-2026-19556

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside

8.3
CVE-2026-66154

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1

7.8
CVE-2026-66150

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows

7.8
CVE-2026-66149

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows

7.1
CVE-2026-63177

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng

8.8
CVE-2026-55676

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P

8.2
CVE-2026-48763

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t

8.2
CVE-2026-19550

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath

8.4
CVE-2026-18634

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (B

8.8
CVE-2026-15606

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i

8.8
CVE-2026-14863

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at

7.8
CVE-2026-73234

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() i

7.5
CVE-2026-73232

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory

7.8
CVE-2026-73231

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method

8.7
CVE-2026-73031

telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary J

7.5
CVE-2026-71467

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent

7.5
CVE-2026-48804

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store

8.1
CVE-2026-19091

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to

8.1
CVE-2026-18844

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (

7.5
CVE-2026-13457

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all

8.1
CVE-2026-73227

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al

8.8
CVE-2026-73226

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al

8.1
CVE-2026-73225

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al

8.8
CVE-2026-73224

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al

8.1
CVE-2026-73223

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al

8.8
CVE-2026-73222

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio

8.6
CVE-2026-72742

DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke

8.3
CVE-2026-69119

Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any aut

7.5
CVE-2026-48809

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw

7.5
CVE-2026-48802

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta

8.1
CVE-2026-18712

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg

7.1
CVE-2026-18711

An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to

7.5
CVE-2026-18697

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce

7.1
CVE-2026-18694

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started