Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 180/1469
7.5
CVE-2026-47193

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint

8.8
CVE-2026-32833

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authe

7.5
CVE-2026-47220

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38

7.2
CVE-2026-13372

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026

8.1
CVE-2026-56876

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file contain

8.6
CVE-2026-55441

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil

7.5
CVE-2026-54341

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload

7.5
CVE-2026-48743

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,

7.5
CVE-2026-48044

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7

7.5
CVE-2026-48042

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,

8.8
CVE-2026-57518

Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage

7.5
CVE-2026-57231

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environ

8.5
CVE-2026-56663

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent

7.5
CVE-2026-55677

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decodi

7.2
CVE-2026-9640

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 reg

7.5
CVE-2026-5757

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to

7.1
CVE-2026-47214

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

7.8
CVE-2026-45195

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor

7.7
CVE-2026-21734

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-

8.4
CVE-2026-12411

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, r

7.5
CVE-2026-0828

Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unpr

8.5
CVE-2026-57667

Sales Representative SQL Injection in Groundhogg <= 4.5 versions.

8.5
CVE-2026-57663

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

8.5
CVE-2026-57662

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

8.8
CVE-2026-57659

Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.

8.2
CVE-2026-57655

Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.

8.5
CVE-2026-57653

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

7.5
CVE-2026-57647

Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.

8.1
CVE-2026-57645

newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

8.5
CVE-2026-57644

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

8.5
CVE-2026-57643

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

8.5
CVE-2026-57642

Contributor SQL Injection in Gallery <= 4.7.8 versions.

8.5
CVE-2026-57636

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

7.6
CVE-2026-57631

Administrator SQL Injection in Popup box <= 6.0.1 versions.

7.6
CVE-2026-57628

Administrator SQL Injection in WP All Import <= 4.0.1 versions.

8.8
CVE-2026-57527

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows

7.1
CVE-2026-57325

Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.

7.1
CVE-2026-57322

Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.

7.1
CVE-2026-57321

Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

7.1
CVE-2026-57319

Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.

7.1
CVE-2026-57317

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

8.5
CVE-2026-57315

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

7.1
CVE-2026-57314

Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

7.1
CVE-2026-57312

Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

8.8
CVE-2026-56773

Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass

7.1
CVE-2026-56072

Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.

7.5
CVE-2026-56069

Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

8.5
CVE-2026-56064

Subscriber SQL Injection in Tourfic <= 2.22.5 versions.

8.3
CVE-2026-56063

Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.

7.5
CVE-2026-56061

Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started