Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 15/1469
7.7
CVE-2026-19851

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attack

7.2
CVE-2026-18328

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based

7.2
CVE-2026-18323

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro

8.8
CVE-2026-16601

The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited

7.8
CVE-2026-69665

SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is e

8.5
CVE-2026-68960

A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is

8.5
CVE-2026-68959

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an

8.5
CVE-2026-68062

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an

7.8
CVE-2026-66109

A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is explo

7.3
CVE-2026-78654

A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of th

8.1
CVE-2026-78478

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes

7.3
CVE-2026-78637

A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdf

8.8
CVE-2026-19892

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to

8.8
CVE-2026-78685

Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote

7.5
CVE-2026-78682

NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.l

7.5
CVE-2026-78681

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations

7.8
CVE-2026-78680

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygrap

7.5
CVE-2026-78677

GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary g

8.4
CVE-2026-78675

GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local f

7.5
CVE-2026-76846

Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access

8.8
CVE-2026-75574

The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as

7.5
CVE-2026-72700

The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation

8.4
CVE-2026-72696

Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local a

8.1
CVE-2026-72695

Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated u

7.5
CVE-2026-56709

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token

7.7
CVE-2026-56707

Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects

7.2
CVE-2026-56703

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not bl

8.8
CVE-2026-56702

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that all

8.1
CVE-2026-34968

Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop actio

7.5
CVE-2026-66766

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vu

8.6
CVE-2026-78284

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

7.1
CVE-2026-78282

Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

7.5
CVE-2026-78268

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Tel

7.1
CVE-2026-78264

Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

7.1
CVE-2026-78263

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

7.3
CVE-2026-78259

Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

7.5
CVE-2026-77384

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh pa

8.8
CVE-2026-32561

Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

8.8
CVE-2026-32560

Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versio

7.1
CVE-2026-32556

Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

7.8
CVE-2026-7455

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A

8.1
CVE-2026-77567

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.

8.1
CVE-2026-75464

OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().

7.4
CVE-2026-56135

In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/sec

7.8
CVE-2026-52492

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result

7.8
CVE-2026-19568

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal

7.8
CVE-2026-16783

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A

7.5
CVE-2026-76098

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS throu

7.1
CVE-2026-75369

An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT

7.5
CVE-2026-75368

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started