Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 9/1469
8.8
CVE-2026-80547

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Implement a crw lock Unlike the cha

7.8
CVE-2026-80546

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Improve CCA CPRB length and overflow c

7.8
CVE-2026-80545

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Improve EP11 CPRB length and overflow

7.8
CVE-2026-80544

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Improve EP11 CPRB domain handling with

7.8
CVE-2026-80541

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate GEM_CREATE domain combinations

7.8
CVE-2026-80540

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD decode image min size calculati

7.1
CVE-2026-80538

In the Linux kernel, the following vulnerability has been resolved: xfs: propagate errors from xfs_rtginode_load xfs_r

7.8
CVE-2026-80537

In the Linux kernel, the following vulnerability has been resolved: xfs: fix off-by-one in rtrefcount btree root level

8.4
CVE-2026-80536

In the Linux kernel, the following vulnerability has been resolved: xfs: bounds-check buffer log item's dirty bitmap x

7.8
CVE-2026-80531

In the Linux kernel, the following vulnerability has been resolved: xfs: avoid UAF on sc->tempip in xrep_tempfile_creat

7.1
CVE-2026-80530

In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue

7.5
CVE-2026-80527

In the Linux kernel, the following vulnerability has been resolved: ceph: fix hanging __ceph_get_caps() with stale mds_

7.8
CVE-2026-80526

In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2562: Validate values for volume writes t

7.1
CVE-2026-80523

In the Linux kernel, the following vulnerability has been resolved: clk: spacemit: k3: set hdma clock as critical HDMA

7.8
CVE-2026-80522

In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - fix rctx->cryptlen calculation in t

7.8
CVE-2026-80521

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle

7.5
CVE-2026-80520

In the Linux kernel, the following vulnerability has been resolved: ovpn: fix NULL dereference when killing missing key

7.8
CVE-2026-74753

In the Linux kernel, the following vulnerability has been resolved: perf: Reject exited events as group leaders perf_e

7.5
CVE-2026-74750

In the Linux kernel, the following vulnerability has been resolved: ovpn: defer key slot crypto freeing to workqueue K

7.8
CVE-2026-74748

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix refcount race between list:se

7.8
CVE-2026-74747

In the Linux kernel, the following vulnerability has been resolved: ipvs: revalidate ihl to prevent out-of-bounds acces

7.5
CVE-2026-74745

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: avoid deadlock when canceling IRQ affini

7.5
CVE-2026-74742

In the Linux kernel, the following vulnerability has been resolved: veth: fix queue index used to wake the peer txq in

7.5
CVE-2026-74741

In the Linux kernel, the following vulnerability has been resolved: net: ngbe: fix NULL pointer dereference in non-MSI-

7.8
CVE-2026-74739

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: skip hash tables in u32_bind_cl

7.8
CVE-2026-74736

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: reject dev-bound programs bound

7.4
CVE-2026-54550

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and

8.6
CVE-2026-54511

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStruc

8.1
CVE-2026-75960

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. Thi

7.5
CVE-2026-73108

RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before

7.5
CVE-2026-19271

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Sof

7.3
CVE-2026-18252

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3

7.5
CVE-2026-15990

The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.

7.8
CVE-2026-77658

A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Di

8.8
CVE-2026-63041

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attack

8.1
CVE-2026-15985

The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all v

7.5
CVE-2026-80205

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear

7.1
CVE-2026-80350

OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms

8.8
CVE-2026-80348

TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods i

7.5
CVE-2026-80347

mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSa

7.1
CVE-2026-80346

StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type

8.2
CVE-2026-77538

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne

8.8
CVE-2026-19042

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote

8.2
CVE-2026-18794

The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by pa

7.5
CVE-2026-16444

Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authen

8.8
CVE-2026-80237

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attack

8.2
CVE-2026-80236

Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can

7.2
CVE-2026-80233

CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability.

7.8
CVE-2026-78237

Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, res

8.8
CVE-2026-78236

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by comm

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started