Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 91/1469
8.8
CVE-2026-64561

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* m

8.0
CVE-2026-16623

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a g

7.3
CVE-2026-42169

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `f

7.2
CVE-2026-14818

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi

7.2
CVE-2026-6837

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions

7.5
CVE-2026-56846

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memor

7.5
CVE-2026-56845

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur

7.1
CVE-2026-66322

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

7.4
CVE-2026-66321

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

8.1
CVE-2026-66318

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

7.5
CVE-2026-66315

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

7.7
CVE-2026-66310

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat

7.4
CVE-2026-65802

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat

8.8
CVE-2026-62870

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-67978

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmittin

7.5
CVE-2026-48399

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a

7.5
CVE-2026-67977

An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause

7.5
CVE-2026-67975

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new s

7.5
CVE-2026-67974

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7

7.5
CVE-2026-67973

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying f

7.5
CVE-2026-67970

Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive co

7.5
CVE-2026-67969

An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset v

8.2
CVE-2026-10849

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser

7.2
CVE-2026-69246

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and

7.5
CVE-2026-67976

The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allo

7.5
CVE-2026-67972

An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data

8.1
CVE-2026-52521

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th

7.8
CVE-2026-41447

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit

8.8
CVE-2026-18733

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors

7.3
CVE-2026-18647

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue

7.5
CVE-2026-69185

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp

7.5
CVE-2026-68981

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding

7.2
CVE-2026-67599

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke

7.4
CVE-2026-67598

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all

7.3
CVE-2026-18641

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by

7.8
CVE-2026-59913

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti

7.8
CVE-2026-59912

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnera

7.5
CVE-2025-15629

A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati

7.5
CVE-2025-15628

Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr

7.5
CVE-2025-15627

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to

7.2
CVE-2026-61524

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th

7.2
CVE-2026-61523

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated

7.5
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3

8.1
CVE-2026-67611

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci

8.1
CVE-2026-67610

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi

7.5
CVE-2026-61372

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Thi

8.8
CVE-2026-41453

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use

7.2
CVE-2026-39931

OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t

7.0
CVE-2026-18718

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exe

8.8
CVE-2026-18607

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started