Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 84/1469
7.5
CVE-2026-65543

Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.

8.8
CVE-2026-65542

Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.

7.3
CVE-2026-65541

Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.

7.5
CVE-2026-65523

Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0

7.1
CVE-2026-65517

Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.

7.1
CVE-2026-65515

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.

7.1
CVE-2026-65513

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.

7.1
CVE-2026-65509

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.

7.5
CVE-2026-65504

Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

7.1
CVE-2026-61982

Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.

7.1
CVE-2026-61964

Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.

7.1
CVE-2026-61963

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.

7.1
CVE-2026-61961

Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.

7.5
CVE-2026-34502

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache

7.5
CVE-2026-34501

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por

7.1
CVE-2026-28177

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

7.1
CVE-2026-28172

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

7.1
CVE-2026-28143

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

7.1
CVE-2026-28141

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

7.5
CVE-2026-28140

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

8.8
CVE-2026-28111

Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

7.1
CVE-2026-28082

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

7.5
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or p

8.7
CVE-2026-16315

OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe

7.5
CVE-2026-66733

Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque

7.5
CVE-2026-65551

Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Securit

7.2
CVE-2026-19036

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp

7.5
CVE-2026-68481

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec

8.1
CVE-2026-57818

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via c

7.2
CVE-2026-19035

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of

7.2
CVE-2025-15028

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is

7.5
CVE-2026-65432

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. Ho

7.5
CVE-2026-64958

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF

7.5
CVE-2026-57819

Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" co

8.1
CVE-2026-57817

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in th

7.5
CVE-2026-54225

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.

7.2
CVE-2026-19034

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_s

8.4
CVE-2026-55978

An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an

7.8
CVE-2026-64601

In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant us

7.8
CVE-2026-64599

In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_cry

8.8
CVE-2026-64598

In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc()

7.8
CVE-2026-64588

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakl

7.0
CVE-2026-64587

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before

8.8
CVE-2026-64586

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device remo

7.8
CVE-2026-64585

In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing net

7.8
CVE-2026-64584

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before

7.8
CVE-2026-64583

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake

7.3
CVE-2026-19021

A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by thi

7.3
CVE-2026-19010

A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag

7.3
CVE-2026-19009

A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started