Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 18/1469
7.4
CVE-2026-10582

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects

8.8
CVE-2026-78317

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-78316

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-78315

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

8.8
CVE-2026-78314

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

7.5
CVE-2026-75975

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6

7.5
CVE-2026-75931

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit

7.5
CVE-2026-75899

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parse

7.3
CVE-2026-78202

A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_

7.3
CVE-2026-78201

A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the fil

7.3
CVE-2026-78199

A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function o

7.3
CVE-2026-78198

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects

7.3
CVE-2026-78197

A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unkn

7.8
CVE-2026-59561

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victi

8.7
CVE-2026-78213

Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attac

7.5
CVE-2026-78212

4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remot

7.3
CVE-2026-78182

A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System

7.3
CVE-2026-78181

A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component K

7.3
CVE-2026-78180

A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider

8.9
CVE-2026-19200

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an impl

7.3
CVE-2026-78178

A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.exte

7.3
CVE-2026-78171

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unkn

8.8
CVE-2026-78170

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formCo

8.2
CVE-2026-78209

exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output.

7.5
CVE-2026-78208

exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate

7.5
CVE-2026-78206

exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, tot

7.1
CVE-2026-78203

Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers t

7.3
CVE-2026-78161

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/

7.4
CVE-2026-78157

A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-pat

7.4
CVE-2026-78156

A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air

7.3
CVE-2026-78147

A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of th

7.3
CVE-2026-78143

A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknow

7.4
CVE-2026-78141

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCo

7.5
CVE-2026-9769

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During Ju

7.5
CVE-2026-4671

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkificatio

8.5
CVE-2026-10053

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 1

7.1
CVE-2026-77115

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without

7.4
CVE-2026-78063

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the

7.3
CVE-2026-78062

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of t

7.8
CVE-2026-78136

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/ken

8.8
CVE-2026-16149

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,

8.8
CVE-2026-0551

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

7.4
CVE-2026-78122

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS en

7.5
CVE-2026-47895

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but no

7.8
CVE-2026-74733

In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regm

7.8
CVE-2026-74731

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Skip sub-disable teardown for never-link

7.3
CVE-2026-74726

In the Linux kernel, the following vulnerability has been resolved: bonding: alb: re-check primary_is_promisc under RTN

7.8
CVE-2026-74725

In the Linux kernel, the following vulnerability has been resolved: enic: fix tx_hang_reset use-after-free on device re

7.8
CVE-2026-74724

In the Linux kernel, the following vulnerability has been resolved: ipvs: avoid out-of-bounds write in ip_vs_nat_icmp

7.8
CVE-2026-74721

In the Linux kernel, the following vulnerability has been resolved: accel/amxdna: Fix page-insertion errors in amdxdna_

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started