Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 47/1469
7.5
CVE-2026-16471

Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Prope

7.2
CVE-2026-16139

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can

8.0
CVE-2026-16138

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file meta

7.2
CVE-2026-16137

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path t

7.9
CVE-2026-15218

A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts

7.1
CVE-2026-75002

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could l

7.2
CVE-2026-74998

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were no

8.8
CVE-2026-74997

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to r

7.5
CVE-2026-16467

Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Pro

8.8
CVE-2026-74893

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation ch

7.5
CVE-2026-74892

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configur

7.5
CVE-2026-74888

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call i

7.5
CVE-2026-74884

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugi

8.8
CVE-2026-74883

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict

7.5
CVE-2026-74882

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private

7.5
CVE-2026-74879

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that return

8.8
CVE-2026-74877

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method th

7.5
CVE-2026-74874

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in

7.7
CVE-2026-74869

stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows auth

7.5
CVE-2026-74868

SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implemen

8.2
CVE-2026-74802

SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy

8.2
CVE-2026-74801

SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the

8.7
CVE-2026-74798

SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs on

8.8
CVE-2026-74845

Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing au

7.1
CVE-2026-74579

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial

8.3
CVE-2026-19983

A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This iss

7.4
CVE-2026-19982

A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code o

7.4
CVE-2026-19981

A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500

7.4
CVE-2026-19980

A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, M

8.3
CVE-2026-19979

A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500

7.4
CVE-2026-19963

A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /go

7.4
CVE-2026-19962

A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /gofo

7.4
CVE-2026-19960

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file

7.5
CVE-2026-74795

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does n

7.5
CVE-2026-74794

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit prop

7.5
CVE-2026-74792

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer pa

8.6
CVE-2026-74791

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cach

7.5
CVE-2026-74789

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expe

7.5
CVE-2026-74788

Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string

7.5
CVE-2026-74787

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks

7.5
CVE-2026-74783

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive des

7.5
CVE-2026-73062

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that

7.5
CVE-2026-73060

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator

7.5
CVE-2026-73057

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause deni

7.5
CVE-2024-58375

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into

7.1
CVE-2026-74578

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processi

7.2
CVE-2026-2497

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parame

7.5
CVE-2026-17087

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization

7.2
CVE-2026-13424

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Sc

7.2
CVE-2026-10734

The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in al

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started