Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 7/1469
7.5
CVE-2026-80433

Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.

7.1
CVE-2026-78293

Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

7.1
CVE-2026-78289

Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

8.5
CVE-2026-78285

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.

7.1
CVE-2026-78283

Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.

7.1
CVE-2026-78281

Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.

7.2
CVE-2026-78276

Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

7.2
CVE-2026-78271

Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

7.1
CVE-2026-78261

Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.

8.8
CVE-2026-78257

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

7.5
CVE-2026-75005

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at

8.5
CVE-2026-32564

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

8.5
CVE-2026-32550

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

8.6
CVE-2026-27330

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

8.8
CVE-2026-78333

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticat

7.5
CVE-2026-78137

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthen

8.8
CVE-2026-77018

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate

7.7
CVE-2026-77017

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine t

7.5
CVE-2026-47893

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by inc

7.5
CVE-2026-47889

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite att

7.5
CVE-2026-47888

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spr

7.5
CVE-2026-47886

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of

7.5
CVE-2026-47885

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -

7.7
CVE-2026-47879

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto de

8.2
CVE-2026-47877

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

7.1
CVE-2026-47849

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Pa

7.5
CVE-2026-19715

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it

7.2
CVE-2026-19223

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an

7.2
CVE-2026-13415

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of it

7.3
CVE-2026-81491

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes

7.3
CVE-2026-81421

A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown functio

7.5
CVE-2026-47852

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.

7.5
CVE-2026-47851

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.

7.3
CVE-2026-81203

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown functio

7.6
CVE-2026-47666

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable t

8.7
CVE-2026-47665

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable t

7.3
CVE-2026-81202

A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete

7.1
CVE-2026-77611

SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal

7.6
CVE-2026-77368

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler

8.1
CVE-2026-77317

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evalu

7.5
CVE-2026-75333

yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new F

7.5
CVE-2026-75328

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitra

7.7
CVE-2026-61617

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13

8.1
CVE-2026-43621

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerabil

7.7
CVE-2026-61792

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

8.1
CVE-2026-55228

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

7.5
CVE-2025-61480

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker

7.5
CVE-2025-61479

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker

7.5
CVE-2025-61478

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker

7.5
CVE-2025-51675

An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR c

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started