Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 73/1469
7.8
CVE-2026-54981

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized

7.5
CVE-2026-54113

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o

7.0
CVE-2026-50472

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-49179

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows a

7.1
CVE-2026-48442

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

8.1
CVE-2026-48440

ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in th

7.5
CVE-2026-48439

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

7.5
CVE-2026-48438

CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application deni

7.5
CVE-2026-48386

ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure

7.7
CVE-2026-48385

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

7.2
CVE-2026-47299

Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an aut

7.8
CVE-2026-42976

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges loca

8.4
CVE-2026-34635

is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low

7.8
CVE-2026-25652

is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged atta

7.4
CVE-2026-22887

Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow

8.2
CVE-2026-21279

is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker co

8.7
CVE-2026-21273

is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged at

7.9
CVE-2026-20891

Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may al

7.3
CVE-2026-20890

Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Proc

7.4
CVE-2026-20795

Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers m

7.8
CVE-2026-20789

Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may al

8.6
CVE-2026-20776

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni

7.4
CVE-2026-20741

Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial

7.4
CVE-2026-20739

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may

8.6
CVE-2026-20349 KEV

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar

8.5
CVE-2026-73079

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0

7.9
CVE-2026-6726

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker wi

8.4
CVE-2026-67180

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing

7.8
CVE-2026-67179

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the develop

8.8
CVE-2026-56721

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference

7.1
CVE-2026-53416

Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca

8.3
CVE-2026-53415

Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code executio

8.3
CVE-2026-53413

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting parti

7.6
CVE-2026-48766

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr

7.1
CVE-2026-48495

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS

7.1
CVE-2026-42142

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee

8.8
CVE-2026-19546

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S

7.1
CVE-2026-18640

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm

7.3
CVE-2026-18639

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s

8.2
CVE-2026-72922

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent

8.1
CVE-2026-72921

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth

8.7
CVE-2026-18860

Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr

7.2
CVE-2026-18635

Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able

8.1
CVE-2026-18129

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a

7.7
CVE-2026-18127

External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica

7.5
CVE-2026-18125

An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated at

8.5
CVE-2026-51583

An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF

8.8
CVE-2026-72781

Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerabili

8.8
CVE-2026-72778

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex

7.5
CVE-2026-72766

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Emai

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started