Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 26/1469
8.1
CVE-2026-28150

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

8.1
CVE-2025-15637

Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

7.5
CVE-2026-73198

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages`

7.5
CVE-2026-73197

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form

8.7
CVE-2026-13097

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attribut

7.8
CVE-2026-18917

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFr

7.5
CVE-2026-14952

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /F

8.0
CVE-2026-14951

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface u

8.8
CVE-2026-14948

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator p

7.2
CVE-2026-14947

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../

7.2
CVE-2026-14946

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to ac

7.5
CVE-2026-75963

The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.

7.2
CVE-2026-15049

The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded throug

7.3
CVE-2026-76795

A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the c

7.3
CVE-2026-76783

A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /pl

7.3
CVE-2026-76764

A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of th

7.3
CVE-2026-76762

A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of

7.5
CVE-2026-76928

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

8.1
CVE-2026-76886

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

7.5
CVE-2026-76880

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

7.5
CVE-2026-76879

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

7.3
CVE-2026-76761

A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file

7.3
CVE-2026-76760

A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate

8.8
CVE-2026-76832

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to re

7.4
CVE-2026-76591

A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of

7.4
CVE-2026-76403

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or a

8.2
CVE-2026-76402

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation

8.1
CVE-2026-76399

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled

8.1
CVE-2026-76397

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant

7.5
CVE-2026-76396

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a sc

8.8
CVE-2026-76395

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the

8.3
CVE-2026-76394

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles c

8.3
CVE-2026-76391

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run search

8.8
CVE-2026-76389

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_ta

8.1
CVE-2026-76388

In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role cou

8.1
CVE-2026-76387

In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the

7.4
CVE-2026-76362

In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOA

7.6
CVE-2026-76357

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the

8.1
CVE-2026-76356

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to a

7.5
CVE-2026-76355

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edg

8.1
CVE-2026-76354

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

8.8
CVE-2026-76352

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

8.8
CVE-2026-76351

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9,

8.8
CVE-2026-76350

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_searc

7.7
CVE-2026-76344

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

8.1
CVE-2026-76338

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trus

7.1
CVE-2026-76336

In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles coul

8.8
CVE-2026-76335

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role w

7.1
CVE-2026-76333

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s

7.1
CVE-2026-76332

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authentic

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started