Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 85/1469
7.5
CVE-2026-18649

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements d

8.5
CVE-2026-18597

The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re

7.2
CVE-2026-18510

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross

7.5
CVE-2026-18050

The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem

7.5
CVE-2026-16734

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe p

8.2
CVE-2026-16268

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetchi

8.2
CVE-2026-14829

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not pr

7.5
CVE-2026-13154

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is pub

7.5
CVE-2026-13153

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes

7.3
CVE-2026-19000

A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/

8.1
CVE-2026-15459

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,

7.2
CVE-2026-18325

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro

7.2
CVE-2026-16636

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for Wo

8.8
CVE-2026-15991

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation

7.3
CVE-2026-18991

A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c

7.3
CVE-2026-18990

A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts o

7.3
CVE-2026-18973

A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz

7.5
CVE-2026-67872

An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queu

7.5
CVE-2026-67871

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddN

7.5
CVE-2026-67869

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_

7.3
CVE-2026-18970

A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected elemen

7.3
CVE-2026-18969

A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is

7.5
CVE-2026-67867

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alar

7.5
CVE-2026-67866

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Lock

7.5
CVE-2026-67863

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when

7.5
CVE-2026-71321

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren

8.1
CVE-2026-71320

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject

7.5
CVE-2026-71316

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries

7.5
CVE-2026-67865

S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denia

7.5
CVE-2026-67864

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement ty

8.1
CVE-2025-63822

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate

8.2
CVE-2026-71315

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules

7.5
CVE-2026-71314

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta

8.0
CVE-2026-71312

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v

7.6
CVE-2026-34966

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass

8.1
CVE-2026-18411

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k

8.4
CVE-2026-17583

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be ed

7.5
CVE-2026-15996

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to

8.1
CVE-2026-70617

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attac

7.5
CVE-2026-69111

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers

8.8
CVE-2026-68746

Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to

8.1
CVE-2026-66881

Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with

8.8
CVE-2026-66298

Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se

8.0
CVE-2026-66297

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l

7.5
CVE-2026-55524

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on

7.8
CVE-2026-55522

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p

7.3
CVE-2026-18958

A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a

8.6
CVE-2026-18953

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp

7.4
CVE-2026-9205

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

8.8
CVE-2026-9201

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started