Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

22,671
Total
48
Known Exploited
Showing 22,671 of 22,671 total · Page 1/454
7.3
CVE-2026-82600

A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the fi

7.3
CVE-2026-82598

A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the comp

7.4
CVE-2026-82597

A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file

7.4
CVE-2026-82595

A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the fil

7.5
CVE-2026-56718

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web ser

8.3
CVE-2026-82549

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component Securi

7.5
CVE-2026-82657

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements

7.5
CVE-2026-82655

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php

8.9
CVE-2026-82654

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rende

8.9
CVE-2026-82653

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package nam

7.1
CVE-2026-82648

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails

8.6
CVE-2026-82645

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/get

7.5
CVE-2026-82644

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which pro

8.8
CVE-2026-82642

Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized wit

8.6
CVE-2026-82641

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication,

7.5
CVE-2026-82639

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that

7.5
CVE-2026-82638

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers t

7.9
CVE-2026-82636

Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an at

8.8
CVE-2026-82635

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads

7.3
CVE-2026-82543

A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage

7.4
CVE-2026-82480

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLeng

7.3
CVE-2026-82478

A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_req

7.5
CVE-2026-75807

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and i

8.1
CVE-2026-82475

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to

7.8
CVE-2026-82474

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode.

8.2
CVE-2026-82473

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verificati

7.5
CVE-2026-82472

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication,

8.7
CVE-2026-82466

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in

8.1
CVE-2026-82463

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the

8.1
CVE-2026-82461

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak

7.8
CVE-2026-82457

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t an

7.1
CVE-2026-82455

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-exi

7.5
CVE-2026-82453

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attacker

8.8
CVE-2026-82450

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that al

8.8
CVE-2026-82447

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first throu

7.5
CVE-2026-77007

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation

7.5
CVE-2026-76586

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount

8.2
CVE-2026-76548

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, gr

7.7
CVE-2026-16600

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does

8.6
CVE-2026-16061

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its

7.7
CVE-2026-41012

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vC

8.6
CVE-2026-55848

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.

7.5
CVE-2026-55841

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylo

7.5
CVE-2026-55784

free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores

7.5
CVE-2026-82333

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted

7.6
CVE-2026-82017

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that

7.1
CVE-2026-81533

An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL state

8.8
CVE-2026-81532

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-

7.5
CVE-2026-81520

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session ope

7.5
CVE-2026-81518

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 22,671 CVE records rated HIGH in our database. Of these, 48 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started