Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 170/1469
7.1
CVE-2026-57344

Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.

7.1
CVE-2026-57343

Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.

8.8
CVE-2026-56037

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Th

8.1
CVE-2026-42382

Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.

7.5
CVE-2026-39448

Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.

7.1
CVE-2026-27430

Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.

7.1
CVE-2026-27426

Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.

7.1
CVE-2026-27425

Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.

8.8
CVE-2026-27414

Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.

8.1
CVE-2026-27412

Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.

7.1
CVE-2026-27408

Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.

7.1
CVE-2026-27404

Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.

7.1
CVE-2026-27402

Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.

8.8
CVE-2026-27060

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This is

7.5
CVE-2026-11946

An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The en

7.1
CVE-2025-69156

Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.

7.1
CVE-2025-69155

Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.

7.1
CVE-2025-69154

Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.

7.1
CVE-2025-69153

Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.

7.1
CVE-2025-69152

Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.

7.5
CVE-2025-69134

Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.

7.5
CVE-2025-69133

Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.

8.5
CVE-2025-69094

Subscriber SQL Injection in Unicamp <= 2.2.2 versions.

8.1
CVE-2025-58902

Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.

7.2
CVE-2026-9834

The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Com

7.5
CVE-2026-8441

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp

8.2
CVE-2026-14336

PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.o

7.5
CVE-2026-13369

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function

7.5
CVE-2026-13251

The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 vi

7.5
CVE-2026-9563

In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max

8.1
CVE-2026-8147

In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper author

7.5
CVE-2026-33592

An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The ser

8.1
CVE-2026-5821

The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4.

7.5
CVE-2026-14249

The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the

8.3
CVE-2026-57278

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57277

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57276

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57275

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57274

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57273

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57272

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57271

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57270

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57269

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57268

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57267

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57266

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57265

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-57264

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

8.3
CVE-2026-13132

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started