Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 25/1469
7.8
CVE-2026-15679

Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This

7.8
CVE-2026-13121

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulne

7.4
CVE-2026-77004

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?met

7.3
CVE-2026-76998

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted elemen

7.5
CVE-2026-75140

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBui

7.5
CVE-2026-63043

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue

8.1
CVE-2026-63042

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the

8.1
CVE-2026-63040

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorizati

7.4
CVE-2026-19611

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can coll

7.3
CVE-2026-76996

A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown fun

7.5
CVE-2026-63490

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handleb

7.8
CVE-2026-61898

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13

7.8
CVE-2026-61897

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching lan

8.2
CVE-2026-49825

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.def

8.8
CVE-2026-16932

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper

7.5
CVE-2026-16928

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-b

7.3
CVE-2026-16927

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-chec

7.1
CVE-2026-16925

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improp

7.5
CVE-2026-16924

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an impro

7.0
CVE-2026-16923

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper p

7.0
CVE-2026-16922

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-ch

7.3
CVE-2026-76990

A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown func

7.8
CVE-2026-76833

@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary J

7.2
CVE-2026-76635

baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administ

8.1
CVE-2026-76633

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authentica

7.3
CVE-2026-76987

A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element

7.6
CVE-2026-74011

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP

7.5
CVE-2026-74021

Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.

7.5
CVE-2026-74020

Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.

7.1
CVE-2026-74019

Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.

8.5
CVE-2026-74013

Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.

8.5
CVE-2026-73998

Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.

7.1
CVE-2026-68564

Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.

7.6
CVE-2026-66677

Subscriber Broken Authentication in Leyka <= 3.32.3 versions.

7.1
CVE-2026-66673

Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.

7.1
CVE-2026-66616

Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.

7.1
CVE-2026-66615

Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.

7.1
CVE-2026-66614

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.

7.1
CVE-2026-66612

Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.

7.1
CVE-2026-66611

Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.

7.1
CVE-2026-66607

Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.

7.1
CVE-2026-66606

Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.

7.1
CVE-2026-66605

Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.

7.1
CVE-2026-66604

Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.

7.1
CVE-2026-66598

Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

7.1
CVE-2026-66597

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.

8.5
CVE-2026-66594

Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

7.1
CVE-2026-66590

Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.

7.1
CVE-2026-66582

Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

7.1
CVE-2026-66581

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started