Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 44/1469
7.1
CVE-2026-66633

Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.

7.1
CVE-2026-66629

Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.

7.5
CVE-2026-66622

Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.

7.1
CVE-2026-66621

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultima

7.2
CVE-2026-66620

Editor PHP Object Injection in OptionTree <= 2.7.3 versions.

7.5
CVE-2026-66046

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAt

8.8
CVE-2026-63639

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command a

8.8
CVE-2026-61407

Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerabi

7.4
CVE-2026-59825

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12,

7.5
CVE-2026-56684

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPending

8.8
CVE-2026-50187

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plug

8.1
CVE-2026-50138

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`),

7.1
CVE-2026-48798

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, Dire

8.3
CVE-2026-45733

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas

7.2
CVE-2026-32553

Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.

7.5
CVE-2026-32549

Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.

7.1
CVE-2026-32547

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.

7.5
CVE-2026-32481

Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.

7.2
CVE-2026-32473

Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.

7.5
CVE-2026-32472

Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.

7.4
CVE-2026-18534

ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing att

7.7
CVE-2026-50575

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted devi

7.5
CVE-2026-32468

Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.

8.5
CVE-2026-32466

Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

8.8
CVE-2026-32465

Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

8.1
CVE-2026-32464

Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.

7.1
CVE-2026-32333

Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.

7.5
CVE-2026-28571

Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.

8.1
CVE-2026-28570

Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.

7.1
CVE-2026-28569

Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.

7.1
CVE-2026-28568

Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.

7.5
CVE-2026-28567

Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.

8.8
CVE-2026-28191

Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.

8.8
CVE-2026-24301

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut

7.3
CVE-2026-75778

A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_

8.1
CVE-2026-74983

Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14

7.5
CVE-2026-74982

Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 1

8.1
CVE-2026-74981

Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR

8.1
CVE-2026-74978

Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird

7.5
CVE-2026-74977

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird

8.8
CVE-2026-74969

Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

7.5
CVE-2026-74966

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, T

8.8
CVE-2026-74965

Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14

8.1
CVE-2026-74962

Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.

8.1
CVE-2026-74960

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fi

7.5
CVE-2026-74958

Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb

8.1
CVE-2026-74957

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firef

8.8
CVE-2026-74955

Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1,

7.5
CVE-2026-74954

Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox

8.8
CVE-2026-74953

Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started