Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 200/1469
8.1
CVE-2026-40761

Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

8.1
CVE-2026-40760

Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

8.1
CVE-2026-40759

Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

8.1
CVE-2026-40758

Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

8.1
CVE-2026-40755

Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

8.1
CVE-2026-40754

Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.

8.1
CVE-2026-40753

Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.

8.1
CVE-2026-40751

Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.

8.1
CVE-2026-40739

Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.

8.1
CVE-2026-40736

Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.

8.1
CVE-2026-40735

Unauthenticated PHP Object Injection in Reina <= 2.1 versions.

8.1
CVE-2026-40731

Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.

8.2
CVE-2026-40726

Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.

7.5
CVE-2026-40721

Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.

8.0
CVE-2026-39598

Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell t

7.1
CVE-2026-39597

Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.

8.1
CVE-2026-39582

Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.

8.1
CVE-2026-39580

Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.

8.1
CVE-2026-39573

Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.

8.1
CVE-2026-39568

Unauthenticated Local File Inclusion in Mr. SEO <= 2.0 versions.

8.1
CVE-2026-39567

Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.

8.1
CVE-2026-39558

Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.

8.1
CVE-2026-39557

Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.

8.1
CVE-2026-39554

Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.

8.1
CVE-2026-39549

Unauthenticated Local File Inclusion in Aperitif <= 1.5 versions.

7.1
CVE-2026-39548

Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.

8.1
CVE-2026-39547

Unauthenticated Local File Inclusion in Getaway < 1.8 versions.

7.6
CVE-2026-39546

Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.

8.1
CVE-2026-39545

Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.

8.1
CVE-2026-39539

Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.

8.1
CVE-2026-39537

Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.

8.1
CVE-2026-39522

Unauthenticated Local File Inclusion in Solene <= 3.4 versions.

8.1
CVE-2026-39446

Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

8.1
CVE-2026-39443

Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.

8.1
CVE-2026-34895

Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.

8.1
CVE-2026-34894

Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions.

8.1
CVE-2026-34893

Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.

7.5
CVE-2026-34888

Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.

7.8
CVE-2026-28615

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead

8.6
CVE-2026-27400

Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.

8.1
CVE-2026-25439

Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.

8.6
CVE-2026-22343

Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.

8.8
CVE-2026-22342

Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions.

7.1
CVE-2026-22339

Unauthenticated Cross Site Scripting (XSS) in WPJobster <= 6.3.5 versions.

8.1
CVE-2026-22338

Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions.

8.5
CVE-2026-22335

Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.

7.5
CVE-2026-22334

Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.

8.1
CVE-2026-22331

Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions.

8.1
CVE-2026-22330

Unauthenticated Local File Inclusion in Right Way <= 4.0 versions.

7.1
CVE-2026-22329

Unauthenticated Cross Site Scripting (XSS) in Skillate <= 1.2.10 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started