Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 105/1469
8.8
CVE-2026-66014

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific condi

7.1
CVE-2026-65922

An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc

8.8
CVE-2026-65921

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written ou

8.8
CVE-2026-65617

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia

8.8
CVE-2026-65616

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administra

8.8
CVE-2026-56748

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authe

8.8
CVE-2026-56747

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a r

8.8
CVE-2026-42017

An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged use

8.1
CVE-2026-42016

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida

7.1
CVE-2026-66759

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl

7.8
CVE-2026-66758

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory alloca

7.5
CVE-2026-12383

A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access control

8.2
CVE-2026-64642

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque

7.5
CVE-2026-64641

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr

8.8
CVE-2026-55578

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the termin

8.8
CVE-2026-54540

Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated term

7.5
CVE-2026-45623

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract

8.8
CVE-2026-17568

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm

7.5
CVE-2026-66731

facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser

7.5
CVE-2026-66730

facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau

7.5
CVE-2026-66729

facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u

7.8
CVE-2026-24252

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of

8.5
CVE-2026-17192

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica

8.4
CVE-2026-66396

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cov

8.7
CVE-2026-66394

SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows

7.5
CVE-2026-59251

Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica

7.5
CVE-2026-58227

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a

7.4
CVE-2026-55953

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in

7.5
CVE-2026-55737

Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can

7.5
CVE-2026-54890

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu

7.5
CVE-2026-42792

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote att

7.6
CVE-2026-66427

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.

7.5
CVE-2026-66050

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows una

7.1
CVE-2026-59558

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

7.1
CVE-2026-59556

Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

7.1
CVE-2026-59553

Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

7.2
CVE-2026-59552

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

8.5
CVE-2026-59551

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

7.5
CVE-2026-59548

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.

7.4
CVE-2026-59546

Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

7.5
CVE-2026-59539

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

7.6
CVE-2026-59537

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versio

7.5
CVE-2026-59536

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

7.3
CVE-2026-59535

Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

7.5
CVE-2026-59534

Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

7.5
CVE-2026-59532

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

7.5
CVE-2026-59531

Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.

7.5
CVE-2026-59530

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

7.5
CVE-2026-59529

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

7.5
CVE-2026-59528

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started