Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 169/1469
7.5
CVE-2026-54409

A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulne

8.6
CVE-2026-54408

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote

8.6
CVE-2026-54407

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote

8.7
CVE-2026-54406

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in s

7.5
CVE-2026-54405

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Net

8.8
CVE-2026-54404

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu

8.6
CVE-2026-54403

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni

7.7
CVE-2026-54401

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to es

8.8
CVE-2026-53358

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels

8.0
CVE-2026-53357

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v

7.8
CVE-2026-12168

An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escal

7.8
CVE-2026-12167

The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access p

7.5
CVE-2026-58652

luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the lu

8.8
CVE-2026-57766

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

8.5
CVE-2026-57765

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

7.1
CVE-2026-57761

Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

8.8
CVE-2026-57759

Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

7.1
CVE-2026-57758

Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

7.1
CVE-2026-57757

Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.

8.5
CVE-2026-57756

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

8.5
CVE-2026-57752

Contributor SQL Injection in iNET Webkit 1.2.4 versions.

8.1
CVE-2026-57751

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

7.5
CVE-2026-57749

Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

7.5
CVE-2026-57748

Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

7.1
CVE-2026-57746

Subscriber Broken Access Control in Booked <= 3.0.0 versions.

8.2
CVE-2026-57688

Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.

8.5
CVE-2026-57687

Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.

7.1
CVE-2026-57686

Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.

7.1
CVE-2026-57682

Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.

7.1
CVE-2026-57678

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider

7.1
CVE-2026-57675

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.

7.1
CVE-2026-57674

Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.

7.1
CVE-2026-57673

Unauthenticated Cross Site Scripting (XSS) in Optimole <= 4.2.7 versions.

7.1
CVE-2026-57672

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions.

7.1
CVE-2026-57671

Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions.

7.1
CVE-2026-57670

Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.

7.1
CVE-2026-57426

Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.

7.1
CVE-2026-57366

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.

7.1
CVE-2026-57362

Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.

7.1
CVE-2026-57361

Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.

7.1
CVE-2026-57360

Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.

7.1
CVE-2026-57359

Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.

7.1
CVE-2026-57358

Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.

7.1
CVE-2026-57357

Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.

7.1
CVE-2026-57356

Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.

7.1
CVE-2026-57351

Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.

7.1
CVE-2026-57350

Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.

7.1
CVE-2026-57349

Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.

7.2
CVE-2026-57348

Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.

7.1
CVE-2026-57345

Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started