Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 8/1469
7.6
CVE-2026-79938

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privil

7.8
CVE-2026-77652

A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/w

8.8
CVE-2026-74770

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS

7.5
CVE-2026-68863

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthentica

8.8
CVE-2026-68861

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS

7.5
CVE-2026-46369

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through

7.5
CVE-2026-26449

In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null poi

7.5
CVE-2026-26447

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same

7.5
CVE-2026-26446

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was alread

7.2
CVE-2026-71171

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an

7.5
CVE-2026-36851

Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

7.5
CVE-2025-61164

Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.

7.5
CVE-2025-61162

Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req

8.8
CVE-2026-58474

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote atta

7.4
CVE-2026-47841

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distr

7.2
CVE-2026-47836

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN reposito

8.8
CVE-2025-56798

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows

8.1
CVE-2026-32258

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.

8.1
CVE-2026-32257

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custo

8.1
CVE-2026-81036

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configu

8.1
CVE-2026-81035

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises th

7.2
CVE-2026-81031

IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The

8.1
CVE-2026-81029

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLogin

8.5
CVE-2026-81027

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a spe

8.4
CVE-2026-80427

bestzip builds the argument list for the system zip utility without separating options from operands. The destination ar

7.1
CVE-2026-80426

FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/s

7.5
CVE-2026-80588

In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path

8.4
CVE-2026-80584

In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and

7.8
CVE-2026-80583

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol acc

7.8
CVE-2026-80582

In the Linux kernel, the following vulnerability has been resolved: drm/shmem_helper: Check VMA boundaries for PMD mapp

7.8
CVE-2026-80580

In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer

7.8
CVE-2026-80579

In the Linux kernel, the following vulnerability has been resolved: fbdev: clear fb_info->mode before deleting a videom

7.3
CVE-2026-80578

In the Linux kernel, the following vulnerability has been resolved: fbdev: core: Fix pointer desynchronization in fb_io

8.8
CVE-2026-80576

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring pack

7.8
CVE-2026-80575

In the Linux kernel, the following vulnerability has been resolved: Input: cs40l50-vibra - validate custom data from us

8.4
CVE-2026-80574

In the Linux kernel, the following vulnerability has been resolved: Input: focaltech - fix array out-of-bounds in focal

7.8
CVE-2026-80572

In the Linux kernel, the following vulnerability has been resolved: Input: byd - synchronize timer deletion before free

7.8
CVE-2026-80570

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - zero report size on F54 wor

7.8
CVE-2026-80569

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F54 report size t

7.8
CVE-2026-80568

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - block s_input when F54 queu

7.8
CVE-2026-80565

In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix error path in devm_qce_register_a

7.8
CVE-2026-80560

In the Linux kernel, the following vulnerability has been resolved: openrisc: signal: do not restore privileged SR bits

7.8
CVE-2026-80559

In the Linux kernel, the following vulnerability has been resolved: Input: sur40 - fix input device registration orderi

7.8
CVE-2026-80556

In the Linux kernel, the following vulnerability has been resolved: mmc: atmel-mci: Fix use-after-free in atmci_remove

7.1
CVE-2026-80555

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Free all memory if cp_init() fails

8.8
CVE-2026-80553

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Cancel existing workqueues The init

8.8
CVE-2026-80552

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure index for read/write regions

7.9
CVE-2026-80550

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Fix out of bounds check on CCW array

8.2
CVE-2026-80549

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Move cp cleanup out of not operation

8.8
CVE-2026-80548

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Selectively expand io_mutex The io_

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started