Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 80/1469
7.6
CVE-2026-19387

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/D

7.3
CVE-2026-19384

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unkno

7.8
CVE-2026-19381

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unkn

7.3
CVE-2026-19379

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of t

7.3
CVE-2026-19376

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class o

7.3
CVE-2026-19374

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affect

7.3
CVE-2026-19355

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of

7.3
CVE-2026-19351

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the

8.8
CVE-2026-19346

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the fi

7.3
CVE-2026-19344

A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown funct

7.3
CVE-2026-19343

A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown function

7.3
CVE-2026-19342

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /i

8.8
CVE-2026-19341

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of t

7.5
CVE-2026-18464

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a

7.5
CVE-2026-18357

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of

7.5
CVE-2026-18032

The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent

8.6
CVE-2026-17044

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it

8.1
CVE-2026-17017

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in

7.5
CVE-2026-16988

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat

7.5
CVE-2026-10595

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen

7.5
CVE-2026-17510

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero leng

7.7
CVE-2026-67620

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity

7.8
CVE-2026-42170

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS f

7.3
CVE-2026-19263

A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted elem

8.1
CVE-2026-16948

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exp

7.5
CVE-2026-16594

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti

7.7
CVE-2026-16589

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL sta

7.5
CVE-2026-16578

The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n

8.1
CVE-2026-16267

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from

7.5
CVE-2026-52880

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable

7.5
CVE-2026-52879

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess

7.5
CVE-2026-52878

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a

8.6
CVE-2026-48120

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be

8.7
CVE-2026-48026

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of th

7.5
CVE-2026-47249

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling

8.8
CVE-2026-48169

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa

7.1
CVE-2026-66061

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS

7.1
CVE-2026-66060

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co

7.5
CVE-2026-65819

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-con

7.5
CVE-2026-62296

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11

7.5
CVE-2026-62295

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11

7.5
CVE-2026-15972

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi

7.3
CVE-2026-48098

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers

7.8
CVE-2026-48097

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers

7.3
CVE-2026-19231

A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects

7.3
CVE-2026-11430

Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu

7.1
CVE-2025-71412

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion

7.1
CVE-2025-71409

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages

7.5
CVE-2025-63235

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON

7.7
CVE-2026-64636

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to rea

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started