Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 90/1469
8.8
CVE-2026-16793

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo

8.2
CVE-2026-47623

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A succ

7.5
CVE-2026-47618

NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause serv

7.5
CVE-2026-47617

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side

7.5
CVE-2026-47616

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side

7.5
CVE-2026-47615

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a

7.5
CVE-2026-47614

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful e

7.5
CVE-2026-47613

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a rest

7.5
CVE-2026-47612

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper lim

7.5
CVE-2026-24255

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash

8.2
CVE-2026-24253

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful expl

8.1
CVE-2026-18830

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute co

7.3
CVE-2026-18788

A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown fun

7.5
CVE-2026-56848

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m

8.8
CVE-2026-18787

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fi

7.5
CVE-2026-15314

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT

8.8
CVE-2026-15307

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse

8.8
CVE-2026-69100

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i

7.6
CVE-2026-25292

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration

7.4
CVE-2026-25288

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

7.5
CVE-2026-24084

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed cap

7.8
CVE-2026-24083

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

7.8
CVE-2026-24080

Memory Corruption when handling malformed request parameters in the fingerprint TA.

8.1
CVE-2026-24079

Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

7.8
CVE-2026-21366

Memory corruption while processing a packet with a size close to the maximum allowed value.

7.5
CVE-2026-67200

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary

7.5
CVE-2026-67198

Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauth

8.8
CVE-2026-67195

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitr

7.3
CVE-2026-18770

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an un

8.8
CVE-2026-18650

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MY

7.1
CVE-2026-11368

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning chann

8.8
CVE-2026-17070

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b

8.8
CVE-2026-70373

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by conc

8.8
CVE-2026-70372

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request pa

8.8
CVE-2026-70371

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request

8.8
CVE-2026-70370

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Colu

8.8
CVE-2026-70369

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-con

7.5
CVE-2026-63252

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message ch

7.5
CVE-2026-62927

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space hand

7.5
CVE-2026-61387

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa

7.4
CVE-2026-60007

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P

8.2
CVE-2026-58080

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On

7.1
CVE-2026-18806

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im

7.8
CVE-2026-10710

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab

7.8
CVE-2026-10709

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab

7.4
CVE-2026-14838

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc.

7.2
CVE-2026-67243

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig

7.3
CVE-2026-18755

A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di

7.8
CVE-2026-64563

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart r

8.8
CVE-2026-64562

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR fr

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started