Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 17/1469
7.5
CVE-2026-66907

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from

7.1
CVE-2026-19685

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued conn

8.8
CVE-2025-36940

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U

7.7
CVE-2026-71366

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Matterm

7.2
CVE-2026-71364

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts

7.5
CVE-2026-21752

HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or

8.8
CVE-2026-13212

The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring

7.5
CVE-2025-68825

HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta

8.0
CVE-2026-78414

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux,

8.1
CVE-2026-39915

TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP hea

8.8
CVE-2026-78376

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory

7.0
CVE-2026-78367

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec

7.3
CVE-2026-78248

A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function

7.5
CVE-2026-76848

TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validati

8.8
CVE-2026-76847

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact

7.4
CVE-2026-76844

webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against

7.8
CVE-2026-76843

The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load sta

8.2
CVE-2026-76842

The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding th

8.8
CVE-2026-76841

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 expos

8.8
CVE-2026-59567

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an un

8.4
CVE-2026-59566

A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Cli

8.8
CVE-2026-59565

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of

7.8
CVE-2026-30512

A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bach

7.4
CVE-2026-21751

HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized

7.3
CVE-2026-78247

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown proc

7.2
CVE-2026-21756

HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to intr

7.6
CVE-2026-78270

Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.

7.3
CVE-2026-78246

A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown c

8.1
CVE-2026-66671

Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

8.1
CVE-2026-66670

Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

7.1
CVE-2026-66623

Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.

7.1
CVE-2026-66610

Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.

7.1
CVE-2026-66599

Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.

7.5
CVE-2026-66585

Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

7.1
CVE-2026-66584

Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.

8.5
CVE-2026-32478

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

8.6
CVE-2026-32477

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.

7.1
CVE-2026-32476

Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.

8.5
CVE-2026-32471

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

7.1
CVE-2026-28190

Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.

8.6
CVE-2026-28171

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

7.5
CVE-2026-28167

Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

7.1
CVE-2026-28166

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

7.1
CVE-2026-28162

Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

7.5
CVE-2026-28153

Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS,

8.1
CVE-2026-28152

Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

8.1
CVE-2026-28151

Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

7.3
CVE-2026-78245

A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the fi

7.3
CVE-2026-78244

A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown f

7.5
CVE-2026-76172

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started