Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 83/1469
8.3
CVE-2026-19140

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rendere

7.4
CVE-2026-19139

Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-le

8.3
CVE-2026-19138

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compro

8.3
CVE-2026-19137

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromise

8.1
CVE-2026-19111

Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Ag

7.3
CVE-2026-19062

A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unkn

7.5
CVE-2026-16620

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist f

7.5
CVE-2026-16619

The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attem

7.5
CVE-2026-13399

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a

7.5
CVE-2026-12584

The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of inco

7.8
CVE-2026-11803

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A mal

7.5
CVE-2026-10599

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transact

7.5
CVE-2026-10524

The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price

8.8
CVE-2024-39024

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

7.5
CVE-2026-68750

Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenti

7.5
CVE-2026-68749

Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthe

7.5
CVE-2026-53985

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's serv

7.5
CVE-2026-53977

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to termi

7.8
CVE-2026-43622

llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1bat

8.6
CVE-2026-3430

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL s

7.5
CVE-2026-18427

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file hand

8.5
CVE-2026-18359

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a re

7.1
CVE-2026-18277

Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remo

8.8
CVE-2026-18258

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScript

7.5
CVE-2026-70646

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` d

7.5
CVE-2026-66712

Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.

7.1
CVE-2026-66711

Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.

8.1
CVE-2026-66710

Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.

8.2
CVE-2026-66708

Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.

7.1
CVE-2026-66707

Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.

7.1
CVE-2026-66705

Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.

7.1
CVE-2026-66702

Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.

7.1
CVE-2026-66694

Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.

7.1
CVE-2026-66690

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.

7.1
CVE-2026-66664

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.

7.1
CVE-2026-66663

Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.

7.1
CVE-2026-66470

Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.

7.1
CVE-2026-66457

Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.

7.1
CVE-2026-66440

Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.

7.1
CVE-2026-66439

Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.

8.1
CVE-2026-65570

Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.

8.5
CVE-2026-65569

Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.

7.1
CVE-2026-65565

Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.

7.1
CVE-2026-65560

Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.

7.2
CVE-2026-65559

Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.

7.1
CVE-2026-65554

Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.

7.2
CVE-2026-65549

Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.

8.5
CVE-2026-65547

Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.

7.1
CVE-2026-65545

Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.

7.1
CVE-2026-65544

Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started