Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 31/1469
7.1
CVE-2026-16570

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string para

7.5
CVE-2026-14861

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verifica

8.8
CVE-2026-14334

The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG

7.2
CVE-2026-13174

The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allow

8.1
CVE-2026-13169

The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modi

8.6
CVE-2026-12983

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowi

8.5
CVE-2026-11565

The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file mana

8.8
CVE-2026-70408

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has adm

8.8
CVE-2026-49419

When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's curr

8.8
CVE-2026-49418

When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range

8.8
CVE-2026-49415

During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated

8.1
CVE-2026-19942

The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress i

7.3
CVE-2026-76050

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of

7.3
CVE-2026-76049

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown functio

7.3
CVE-2026-76048

A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown funct

7.3
CVE-2026-75987

A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of

7.3
CVE-2026-75986

A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown functio

7.4
CVE-2026-75985

A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/pin

7.4
CVE-2026-75984

A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admi

8.8
CVE-2026-66602

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Reque

7.6
CVE-2026-53958

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to

8.3
CVE-2026-52877

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the op

8.8
CVE-2026-52876

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the op

8.8
CVE-2026-52872

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSu

8.6
CVE-2026-52854

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to vers

8.8
CVE-2026-50191

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account tak

8.8
CVE-2026-50186

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project

7.5
CVE-2026-50142

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted b

8.8
CVE-2026-76047

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside

8.3
CVE-2026-76046

Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compro

8.8
CVE-2026-76045

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code ins

8.3
CVE-2026-76044

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the rendere

8.8
CVE-2026-76043

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code

8.8
CVE-2026-76040

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social

8.8
CVE-2026-76038

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside

8.4
CVE-2026-76037

Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to

8.8
CVE-2026-76034

Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code ou

8.6
CVE-2026-73939

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.5
CVE-2026-73938

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

8.2
CVE-2026-73937

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.5
CVE-2026-73936

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.5
CVE-2026-73935

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.5
CVE-2026-73934

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.3
CVE-2026-73933

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

8.3
CVE-2026-73931

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

8.3
CVE-2026-73929

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.2
CVE-2026-73928

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.5
CVE-2026-73927

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

8.2
CVE-2026-73925

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.3
CVE-2026-73918

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started