Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 111/1469
8.7
CVE-2026-47743

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed

7.5
CVE-2026-44909

Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate

8.8
CVE-2026-65917

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in

8.1
CVE-2026-65916

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre

7.0
CVE-2026-16584

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to

7.5
CVE-2026-15615

Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and

7.5
CVE-2026-15614

Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid

7.5
CVE-2026-43823

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c

7.7
CVE-2026-43820

NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to

7.2
CVE-2026-65898

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute

8.8
CVE-2026-65690

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file

7.5
CVE-2026-14257

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the

8.6
CVE-2026-65908

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on un

8.8
CVE-2026-65906

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

8.8
CVE-2026-65897

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing au

7.1
CVE-2026-65896

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in th

8.5
CVE-2026-65895

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, a

8.8
CVE-2026-65608

Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField()

7.1
CVE-2026-65540

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

7.1
CVE-2026-65539

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

7.6
CVE-2026-65532

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

8.5
CVE-2026-65526

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualiz

7.2
CVE-2026-65516

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

7.1
CVE-2026-65511

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.

7.1
CVE-2026-65510

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

7.5
CVE-2026-65500

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ver

7.2
CVE-2026-65497

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

7.5
CVE-2026-65495

Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.

7.1
CVE-2026-65494

Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.

7.5
CVE-2026-65493

Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

7.1
CVE-2026-65492

Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.

7.1
CVE-2026-65488

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

7.5
CVE-2026-65481

Contributor Local File Inclusion in Vino <= 1.9 versions.

7.5
CVE-2026-65477

Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

7.6
CVE-2026-65462

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

8.5
CVE-2026-65454

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

8.5
CVE-2026-65451

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

8.5
CVE-2026-65450

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

8.1
CVE-2026-64815

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

8.6
CVE-2026-64814

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

7.8
CVE-2026-64811

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via develop

8.4
CVE-2026-64809

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur

8.4
CVE-2026-64808

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tool

7.8
CVE-2026-64807

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

8.4
CVE-2026-64806

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur

8.4
CVE-2026-64805

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca

8.4
CVE-2026-64804

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca

7.8
CVE-2026-64803

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured

7.8
CVE-2026-64802

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules

7.5
CVE-2026-61954

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started