Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 103/1469
8.5
CVE-2026-49332

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X

7.5
CVE-2026-42493

Addressing certain issues, in particular related to operations which may take excessively long and therefore would need

7.5
CVE-2026-42492

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To m

7.5
CVE-2026-15025

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to

7.2
CVE-2026-13440

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for

7.5
CVE-2026-14785

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver

8.8
CVE-2026-14328

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil

7.5
CVE-2026-10207

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.

7.2
CVE-2026-61376

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings.

7.2
CVE-2026-59764

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu

7.5
CVE-2026-14516

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec

8.1
CVE-2026-14169

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted in

8.8
CVE-2026-14168

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th

8.8
CVE-2026-14167

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu

7.5
CVE-2026-13161

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi

7.5
CVE-2026-12800

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'

7.5
CVE-2026-12741

The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via t

7.2
CVE-2026-16585

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbi

7.5
CVE-2026-14924

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in

7.1
CVE-2026-14870

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and e

7.5
CVE-2026-14490

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory D

7.5
CVE-2026-17524

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path va

7.5
CVE-2026-66473

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

7.1
CVE-2026-65447

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

7.1
CVE-2026-65446

Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

7.1
CVE-2026-65443

Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

7.2
CVE-2026-65442

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

7.1
CVE-2026-65441

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

7.1
CVE-2026-65440

Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

7.1
CVE-2026-65439

Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

7.1
CVE-2026-65438

Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

7.1
CVE-2026-65437

Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.

7.1
CVE-2026-61957

Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

7.2
CVE-2026-61953

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

7.5
CVE-2025-63913

An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI fu

7.5
CVE-2026-55685

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauth

7.5
CVE-2026-51078

An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the fil

7.5
CVE-2026-51077

SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlqu

8.8
CVE-2021-32087

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credent

8.8
CVE-2021-32085

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credent

8.8
CVE-2026-64783

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and i

8.1
CVE-2026-64768

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS

7.8
CVE-2026-64766

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10,

7.8
CVE-2026-64765

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10,

7.8
CVE-2026-64764

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS

7.8
CVE-2026-64763

An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.10 and iPadO

7.8
CVE-2026-64758

The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6,

8.8
CVE-2026-64757

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10

7.8
CVE-2026-64749

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 a

7.8
CVE-2026-64747

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started