Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 92/1469
7.8
CVE-2026-18606

A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown function

7.0
CVE-2026-18605

A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library A

7.5
CVE-2026-18568

XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when ev

7.8
CVE-2026-67609

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatio

7.0
CVE-2026-69097

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitra

8.8
CVE-2026-69096

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after

7.5
CVE-2026-69095

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in

7.5
CVE-2026-69091

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only

7.5
CVE-2026-69089

Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image

8.1
CVE-2026-69088

Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint

7.7
CVE-2026-69086

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,

8.6
CVE-2026-68587

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea

8.6
CVE-2026-68586

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints

8.6
CVE-2026-68584

SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end

7.2
CVE-2026-67608

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti

7.8
CVE-2026-18642

Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock

8.8
CVE-2026-18600

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s

8.1
CVE-2026-18092

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm

7.5
CVE-2026-18089

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em

8.0
CVE-2026-18599

A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f

8.8
CVE-2026-18598

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_l

7.5
CVE-2026-21555

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21554

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21553

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21552

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21551

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21550

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21549

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21548

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System exec

7.3
CVE-2026-4793

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or wr

7.5
CVE-2026-18587

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component

8.6
CVE-2026-16572

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a

8.1
CVE-2026-16539

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a S

8.1
CVE-2025-15672

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa

7.5
CVE-2026-14682

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This i

7.5
CVE-2026-13586

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also a

7.5
CVE-2026-13506

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects B

7.5
CVE-2026-12852

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

7.8
CVE-2026-20495

In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local e

7.7
CVE-2026-20483

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local es

7.5
CVE-2026-20479

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv

8.1
CVE-2026-20465

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (pro

7.1
CVE-2026-65875

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens

7.5
CVE-2026-59646

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This is

7.5
CVE-2026-59645

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. T

7.5
CVE-2026-59642

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue

7.5
CVE-2026-59639

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue al

8.2
CVE-2026-15055

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a

8.6
CVE-2026-12185

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i

7.5
CVE-2026-3245

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started