Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 181/1469
7.5
CVE-2026-56060

Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.

8.8
CVE-2026-56055

Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.

7.1
CVE-2026-56047

Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.

7.1
CVE-2026-56045

Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

7.1
CVE-2026-56044

Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

7.1
CVE-2026-56043

Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

7.1
CVE-2026-56041

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.

7.1
CVE-2026-56040

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

7.1
CVE-2026-56039

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.

8.8
CVE-2026-56038

Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

8.6
CVE-2026-56035

Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.

8.1
CVE-2026-56031

Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

7.5
CVE-2026-56029

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

7.5
CVE-2026-56025

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

7.1
CVE-2026-56011

Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

8.8
CVE-2026-56010

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

8.8
CVE-2026-56008

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

7.5
CVE-2026-54847

Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.

7.5
CVE-2026-54846

Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.

7.3
CVE-2026-54840

Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.

7.5
CVE-2026-54839

Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups

7.5
CVE-2026-54837

Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.

7.5
CVE-2026-54835

Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.

7.5
CVE-2026-54834

Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.

7.4
CVE-2026-54833

Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

7.5
CVE-2026-54832

Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.

7.6
CVE-2026-54826

Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.

7.5
CVE-2026-54824

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

7.8
CVE-2026-45257

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and s

7.5
CVE-2026-30041

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code

7.5
CVE-2025-68064

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

7.5
CVE-2025-68063

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versio

8.8
CVE-2025-68052

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

7.7
CVE-2026-57920

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai

7.3
CVE-2026-57915

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized

8.0
CVE-2026-40711

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-po

7.1
CVE-2026-57918

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d

7.5
CVE-2026-57913

Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transc

7.5
CVE-2026-57912

Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes e

7.5
CVE-2026-11702

Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an objec

7.5
CVE-2026-11625

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is in

8.6
CVE-2026-57877

An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.

7.5
CVE-2026-57876

An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 an

7.5
CVE-2026-57875

An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI compo

7.5
CVE-2026-57874

An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V

7.5
CVE-2026-57873

An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-

7.5
CVE-2026-57872

An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.1

7.5
CVE-2026-49486

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p(

8.3
CVE-2026-2053

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or

7.7
CVE-2026-10835

The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started