Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 112/1469
7.1
CVE-2026-61947

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

7.1
CVE-2026-61944

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

7.5
CVE-2026-61943

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

7.5
CVE-2026-59554

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

7.5
CVE-2026-59547

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

8.1
CVE-2026-59545

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

7.7
CVE-2026-59542

Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

8.8
CVE-2026-59541

Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

7.1
CVE-2026-59517

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

7.1
CVE-2026-59512

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

7.1
CVE-2026-57809

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.

8.8
CVE-2026-57785

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

7.1
CVE-2026-57769

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

7.1
CVE-2026-57767

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

7.1
CVE-2026-57735

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

7.1
CVE-2026-57704

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

7.1
CVE-2026-57701

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

7.1
CVE-2026-57699

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

7.1
CVE-2026-57696

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

7.1
CVE-2026-57626

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailP

7.1
CVE-2026-57428

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

7.1
CVE-2026-57427

Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

7.1
CVE-2026-57397

Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.

7.1
CVE-2026-57374

Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.

7.1
CVE-2026-57370

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.

7.1
CVE-2026-57367

Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.

8.5
CVE-2026-25405

Contributor SQL Injection in eRoom <= 1.7.1 versions.

8.5
CVE-2026-24552

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All

7.5
CVE-2026-64611

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing

8.8
CVE-2026-16745

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network b

8.1
CVE-2026-65757

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - T

7.5
CVE-2026-65755

Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio

7.5
CVE-2026-65754

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths c

7.5
CVE-2026-65430

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in

8.8
CVE-2026-64876

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-up

7.5
CVE-2026-64799

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions

8.8
CVE-2026-15017

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin

7.5
CVE-2026-52688

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

7.8
CVE-2026-16287

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG

7.5
CVE-2024-58330

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret

8.4
CVE-2024-58023

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform

7.5
CVE-2026-9713

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'

7.2
CVE-2026-12421

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version

7.5
CVE-2026-14291

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its

7.5
CVE-2026-12082

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes

7.2
CVE-2026-7534

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST AP

7.2
CVE-2026-7232

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in

7.8
CVE-2026-64600

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling I

7.5
CVE-2026-15074

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the

7.3
CVE-2026-16632

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started