Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 43/1469
8.3
CVE-2026-49224

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

7.6
CVE-2026-49223

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

7.6
CVE-2026-49222

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

8.6
CVE-2026-75926

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, B

7.5
CVE-2026-75915

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fa

7.5
CVE-2026-75914

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonica

7.4
CVE-2026-75912

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers

7.8
CVE-2026-75911

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config f

7.5
CVE-2026-75859

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attacker

7.8
CVE-2026-75858

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerabi

7.0
CVE-2026-75857

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool,

8.6
CVE-2026-75856

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to p

7.7
CVE-2026-71365

A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing

8.7
CVE-2026-55839

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/sr

7.6
CVE-2026-49227

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

8.3
CVE-2026-49226

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

8.8
CVE-2026-49221

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

8.7
CVE-2026-45116

MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox a

8.7
CVE-2026-45115

MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames cor

8.8
CVE-2026-19501

CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula chara

7.5
CVE-2026-19500

The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-

8.5
CVE-2026-75898

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (age

8.8
CVE-2026-74012

Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: fro

7.5
CVE-2026-73997

Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

7.5
CVE-2026-73994

Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.

8.1
CVE-2026-73400

Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.

7.1
CVE-2026-73396

Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.

7.1
CVE-2026-73393

Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.

7.1
CVE-2026-73382

Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.

7.1
CVE-2026-73378

Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.

7.5
CVE-2026-73377

Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.

7.1
CVE-2026-73375

Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.

7.2
CVE-2026-73367

Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.

7.1
CVE-2026-73362

Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.

7.1
CVE-2026-73361

Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.

7.1
CVE-2026-73360

Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.

7.1
CVE-2026-73358

Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.

8.2
CVE-2026-73356

Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.

7.1
CVE-2026-73351

Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.

8.2
CVE-2026-73350

Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.

7.1
CVE-2026-73345

Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.

7.1
CVE-2026-73342

Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.

7.1
CVE-2026-73338

Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.

7.1
CVE-2026-73190

Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.

7.5
CVE-2026-73181

Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.

7.6
CVE-2026-69189

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLH

7.1
CVE-2026-68567

Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.

8.8
CVE-2026-66793

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernet

7.1
CVE-2026-66667

Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.

7.4
CVE-2026-66635

Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started