Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 199/1469
7.3
CVE-2025-69189

Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Leve

8.1
CVE-2025-69175

Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

8.1
CVE-2025-69174

Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

8.1
CVE-2025-69170

Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

8.1
CVE-2025-69166

Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

8.1
CVE-2025-69164

Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.

8.1
CVE-2025-69158

Unauthenticated Local File Inclusion in Granola <= 1.13 versions.

8.1
CVE-2025-69157

Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.

8.1
CVE-2025-69144

Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.

7.1
CVE-2025-69140

Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

8.8
CVE-2025-69130

Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.

8.6
CVE-2025-69128

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Pat

8.1
CVE-2025-69126

Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.

8.1
CVE-2025-69123

Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.

8.1
CVE-2025-69120

Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.

8.1
CVE-2025-69115

Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.

8.1
CVE-2025-69106

Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.

7.1
CVE-2025-68524

Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.

8.8
CVE-2025-66391

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write o

7.5
CVE-2026-9690

Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.

7.1
CVE-2026-9570

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline

7.1
CVE-2026-8089

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin

8.8
CVE-2026-54805

Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

7.6
CVE-2026-54804

Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.

7.5
CVE-2026-54802

Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.

7.1
CVE-2026-54195

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.

7.1
CVE-2026-54192

Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.

7.1
CVE-2026-54189

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

7.1
CVE-2026-54188

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

8.5
CVE-2026-54185

Subscriber SQL Injection in Cornerstone < 7.8.8 versions.

8.2
CVE-2026-54184

Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.

7.2
CVE-2026-53876

RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary c

7.4
CVE-2026-52698

Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2

7.5
CVE-2026-52696

Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.

7.1
CVE-2026-49778

Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.

8.5
CVE-2026-49113

Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.

8.2
CVE-2026-49081

Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.

7.1
CVE-2026-49074

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.

8.5
CVE-2026-49073

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist

7.5
CVE-2026-49057

Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.

8.5
CVE-2026-48967

Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.

7.5
CVE-2026-48929

Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthent

7.1
CVE-2026-48869

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

8.2
CVE-2026-48788

Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Version

7.5
CVE-2026-48779

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, f

8.8
CVE-2026-42629

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

7.1
CVE-2026-42385

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

7.1
CVE-2026-41557

Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.

7.3
CVE-2026-40768

Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.

7.1
CVE-2026-40765

Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started