Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 201/1469
7.1
CVE-2026-22328

Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions.

8.1
CVE-2026-22326

Unauthenticated Local File Inclusion in Reprizo <= 1.0.8 versions.

8.1
CVE-2026-22325

Unauthenticated Local File Inclusion in Promo <= 1.3.0 versions.

8.3
CVE-2026-12468

Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the render

8.3
CVE-2026-12467

Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the

8.8
CVE-2026-12466

Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute

8.3
CVE-2026-12465

Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised

8.3
CVE-2026-12464

Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the ren

7.5
CVE-2026-12462

Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the rende

7.5
CVE-2026-12455

Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to e

8.3
CVE-2026-12454

Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the

8.8
CVE-2026-12452

Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially

8.3
CVE-2026-12451

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromi

7.8
CVE-2026-12449

Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-

8.8
CVE-2026-12448

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to

8.8
CVE-2026-12447

Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary c

7.5
CVE-2026-12445

Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to instal

8.8
CVE-2026-12443

Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbit

8.8
CVE-2026-12442

Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arb

8.8
CVE-2026-12441

Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially

8.8
CVE-2026-12439

Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially

8.3
CVE-2026-12438

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker wh

8.3
CVE-2026-12437

Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had comprom

7.5
CVE-2026-12360

The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The list

8.8
CVE-2026-12256

Contributor PHP Object Injection in Avada <= 3.15.3 versions.

7.5
CVE-2026-12199

A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNe

8.8
CVE-2026-12165

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privi

7.2
CVE-2026-11410

An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR9

7.2
CVE-2026-11409

An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due t

7.0
CVE-2026-0083

In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local e

7.8
CVE-2026-0082

In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to

7.8
CVE-2026-0081

In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escala

7.8
CVE-2026-0071

In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local

7.8
CVE-2026-0068

In createSessionInternal of PackageInstallerService.java, there is a possible method to remove a DPC app from a managed

7.8
CVE-2026-0063

In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a lo

7.8
CVE-2026-0019

In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead t

8.1
CVE-2025-69178

Unauthenticated Local File Inclusion in Truemag <= 4.3.14.2 versions.

8.1
CVE-2025-69177

Unauthenticated Local File Inclusion in Roneous <= 2.1.5 versions.

8.1
CVE-2025-69176

Unauthenticated Local File Inclusion in ITactics <= 1.0 versions.

8.1
CVE-2025-69173

Unauthenticated Local File Inclusion in Tipsy <= 1.1 versions.

8.1
CVE-2025-69172

Unauthenticated Local File Inclusion in Resurs <= 1.3 versions.

8.1
CVE-2025-69171

Unauthenticated Local File Inclusion in Orpheus <= 1.3 versions.

8.1
CVE-2025-69168

Unauthenticated Local File Inclusion in Spike <= 1.2 versions.

8.1
CVE-2025-69167

Unauthenticated Local File Inclusion in Eros <= 1.3 versions.

8.1
CVE-2025-69165

Unauthenticated Local File Inclusion in Choreo <= 1.6 versions.

8.1
CVE-2025-69163

Unauthenticated Local File Inclusion in WineShop <= 3.17 versions.

8.1
CVE-2025-69162

Unauthenticated Local File Inclusion in Grecko <= 5.17 versions.

8.1
CVE-2025-69161

Unauthenticated Local File Inclusion in Snowy <= 1.13 versions.

8.1
CVE-2025-69160

Unauthenticated Local File Inclusion in Gita <= 1.11 versions.

8.1
CVE-2025-69159

Unauthenticated Local File Inclusion in Printo <= 1.11 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started