Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 79/1469
7.6
CVE-2026-72594

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic

7.7
CVE-2026-72591

A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t

7.5
CVE-2026-72586

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que

7.4
CVE-2026-72584

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac

7.5
CVE-2026-72582

A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras

8.6
CVE-2026-72581

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker

7.5
CVE-2026-72579

An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept

8.8
CVE-2026-72578

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to

8.8
CVE-2026-72573

An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execut

7.5
CVE-2026-72572

A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and down

7.5
CVE-2026-72571

A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker t

7.7
CVE-2026-72566

A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authent

7.3
CVE-2026-65948

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option f

7.5
CVE-2026-65942

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to v

7.5
CVE-2026-61899

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets v

7.8
CVE-2026-59087

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote

7.5
CVE-2026-55814

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version

7.5
CVE-2026-44630

Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus

8.1
CVE-2026-66407

DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket privat

8.8
CVE-2026-66405

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to th

7.5
CVE-2026-66403

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log informatio

7.8
CVE-2026-21072

Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write o

7.8
CVE-2026-21071

Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write

7.8
CVE-2026-21069

Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local att

7.8
CVE-2026-21068

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execut

7.8
CVE-2026-21067

Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds me

7.8
CVE-2026-21066

Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write ou

7.8
CVE-2026-21065

Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bo

8.6
CVE-2026-64940

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular exp

7.1
CVE-2026-21059

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attac

7.1
CVE-2026-21058

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with

8.6
CVE-2026-19049

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries,

7.5
CVE-2026-18946

The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded thr

8.8
CVE-2026-18786

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and

7.5
CVE-2026-18470

The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the a

8.1
CVE-2026-18469

The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a se

8.1
CVE-2026-18468

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the acc

8.1
CVE-2026-18030

The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password

7.5
CVE-2026-17542

The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connecto

7.5
CVE-2026-17541

The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowin

8.8
CVE-2026-17540

The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any au

7.5
CVE-2026-17022

The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before

8.8
CVE-2026-16985

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data writ

8.2
CVE-2026-16257

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, wh

8.8
CVE-2026-14293

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option

7.2
CVE-2026-14237

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorizat

7.5
CVE-2026-14206

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns

8.1
CVE-2026-13600

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before settin

7.2
CVE-2026-13170

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to includ

7.1
CVE-2026-19389

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdem

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started