Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 206/1469
8.8
CVE-2024-24909

Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the ga

8.2
CVE-2026-48780

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address cou

7.7
CVE-2026-47684

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version

7.5
CVE-2026-12398

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (

8.1
CVE-2026-12328

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbir

8.1
CVE-2026-12327

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these

8.1
CVE-2026-12326

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption a

7.3
CVE-2026-12324

Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firef

7.3
CVE-2026-12318

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunder

7.5
CVE-2026-12317

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

7.5
CVE-2026-12314

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

7.5
CVE-2026-12312

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

7.5
CVE-2026-12310

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

7.5
CVE-2026-12305

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

8.1
CVE-2026-12292

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.1

8.8
CVE-2026-12291

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef

8.1
CVE-2026-12290

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115

8.8
CVE-2026-12289

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.

8.1
CVE-2026-8442

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 1

7.5
CVE-2026-8176

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca

8.8
CVE-2026-5416

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exp

7.1
CVE-2026-54198

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.

7.1
CVE-2026-54191

Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.

7.6
CVE-2026-52712

Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.

7.5
CVE-2026-52711

Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.

8.5
CVE-2026-39581

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

7.5
CVE-2026-39490

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

7.1
CVE-2026-39437

Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.

7.5
CVE-2025-68045

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

8.8
CVE-2026-8444

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpf

7.8
CVE-2026-46331

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page ca

8.8
CVE-2026-8443

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter

8.8
CVE-2026-6933

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in version

8.8
CVE-2026-7273

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABT

8.8
CVE-2026-12161

Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or mo

7.8
CVE-2026-48723

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions pri

8.8
CVE-2026-48017

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate

7.1
CVE-2026-52702

Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

8.5
CVE-2026-52700

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

7.5
CVE-2026-52699

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

8.5
CVE-2026-52697

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

7.5
CVE-2026-52695

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

7.5
CVE-2026-52694

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

7.5
CVE-2026-52692

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

8.8
CVE-2026-49780

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

7.5
CVE-2026-49112

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

7.5
CVE-2026-49110

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.

7.5
CVE-2026-49083

Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.

7.4
CVE-2026-49082

Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Custome

7.5
CVE-2026-49078

Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started