Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 30/1469
8.8
CVE-2026-75918

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled.

8.6
CVE-2026-75917

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (a

8.6
CVE-2026-75916

SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup.

8.8
CVE-2026-71694

An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619

8.1
CVE-2026-70422

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

7.2
CVE-2026-70421

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high pri

7.1
CVE-2026-56088

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

7.2
CVE-2026-54796

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

8.8
CVE-2026-54795

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

7.2
CVE-2026-54794

Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An una

7.5
CVE-2026-51367

An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the a

7.8
CVE-2026-43961

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can brea

8.8
CVE-2024-58376

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAli

7.5
CVE-2020-37267

Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in serv

7.5
CVE-2019-25766

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain G

7.5
CVE-2026-76235

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated requ

7.5
CVE-2026-73394

Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.

8.1
CVE-2026-73387

Unauthenticated Local File Inclusion in Resido <= 1.5 versions.

7.5
CVE-2026-73386

Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.

7.5
CVE-2026-73385

Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.

7.5
CVE-2026-73384

Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.

7.1
CVE-2026-73354

Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.

7.1
CVE-2026-73184

Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.

7.1
CVE-2026-73182

Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.

8.5
CVE-2026-66668

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

7.1
CVE-2026-66596

Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.

7.1
CVE-2026-61986

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.

8.5
CVE-2026-32552

Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.

7.5
CVE-2026-75589

Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time

7.4
CVE-2026-58088

The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program h

7.8
CVE-2026-58087

The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protec

8.1
CVE-2026-58086

As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing

7.5
CVE-2026-58085

After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC

8.4
CVE-2026-58083

While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqu

7.2
CVE-2026-75981

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthentica

7.2
CVE-2026-15780

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored C

7.8
CVE-2026-49430

The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for

7.8
CVE-2026-49429

The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer fo

8.4
CVE-2026-49428

Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepa

8.8
CVE-2026-49427

Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an obje

8.4
CVE-2026-49422

The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires th

7.1
CVE-2026-49421

The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pas

8.8
CVE-2026-49420

The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewr

8.8
CVE-2026-19842

The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing t

7.1
CVE-2026-19056

The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it i

7.1
CVE-2026-19055

The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecti

7.2
CVE-2026-17565

The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using i

8.6
CVE-2026-16950

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it i

8.8
CVE-2026-16617

The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before o

8.6
CVE-2026-16616

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachabl

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started