Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 81/1469
7.5
CVE-2026-19082

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count

7.1
CVE-2026-71556

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree opera

8.0
CVE-2026-68772

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attacke

7.5
CVE-2026-20348

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

7.5
CVE-2026-20347

A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do

7.5
CVE-2026-20346

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

7.5
CVE-2026-20345

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

7.5
CVE-2026-20339

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do

7.5
CVE-2026-20338

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi

7.5
CVE-2026-20337

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi

7.3
CVE-2026-19211

A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /socia

7.1
CVE-2026-18497

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p

8.2
CVE-2026-66838

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr

7.7
CVE-2026-56793

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An

7.5
CVE-2026-15816

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs

7.5
CVE-2026-71559

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de

8.8
CVE-2026-9169

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitr

7.5
CVE-2026-49007

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th

7.3
CVE-2026-19196

A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the

8.8
CVE-2026-16263

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p

7.5
CVE-2026-16262

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating

7.5
CVE-2026-16041

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p

8.1
CVE-2026-16030

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t

8.1
CVE-2026-15361

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n

8.8
CVE-2026-15215

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing

7.5
CVE-2026-14943

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d

7.8
CVE-2026-19195

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th

7.8
CVE-2026-19193

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys

7.8
CVE-2026-19192

A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C

7.8
CVE-2026-19191

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o

7.8
CVE-2026-19190

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Fil

7.1
CVE-2026-49746

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor

7.8
CVE-2026-45198

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G

7.8
CVE-2026-19189

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional

8.8
CVE-2026-65668

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo

7.5
CVE-2026-62918

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing

8.7
CVE-2026-62836

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized

8.8
CVE-2026-49163

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a

7.8
CVE-2026-8325

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A ma

7.8
CVE-2026-7867

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec

7.8
CVE-2026-7406

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference

7.5
CVE-2026-71488

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially craf

7.0
CVE-2026-70640

llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrap

7.8
CVE-2026-70638

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where th

7.5
CVE-2026-70636

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th

7.1
CVE-2026-70635

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica

8.1
CVE-2026-70634

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression revers

7.8
CVE-2026-70632

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native G

7.8
CVE-2026-70628

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtit

7.5
CVE-2026-70559

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started