Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 88/1469
7.2
CVE-2026-7693

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.

8.1
CVE-2026-7520

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin

8.1
CVE-2026-7444

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and

7.5
CVE-2026-71215

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and ext

7.1
CVE-2026-71211

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr

7.5
CVE-2026-71209

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes agai

8.3
CVE-2026-71206

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded

7.5
CVE-2026-71202

The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only cl

7.5
CVE-2026-70378

imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is posit

7.5
CVE-2026-70377

imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * rat

7.5
CVE-2026-6639

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all

8.2
CVE-2026-6627

The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a

8.8
CVE-2026-6147

The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th

7.3
CVE-2026-6079

The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing

7.2
CVE-2026-6020

The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action

7.8
CVE-2026-64581

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_pol

7.8
CVE-2026-64580

In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netde

8.2
CVE-2026-64578

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before readin

7.5
CVE-2026-64577

In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_ech

7.1
CVE-2026-64576

In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate

7.8
CVE-2026-64575

In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc

7.8
CVE-2026-64574

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update e

7.8
CVE-2026-64570

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on a

7.8
CVE-2026-64568

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double f

7.8
CVE-2026-64567

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries th

7.5
CVE-2026-61485

** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af

7.5
CVE-2026-61483

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al

7.5
CVE-2026-59675

When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz

8.8
CVE-2026-55997

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token

8.3
CVE-2026-55739

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability ch

8.1
CVE-2026-54418

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable,

7.2
CVE-2026-54416

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i

7.5
CVE-2026-18881

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter

7.5
CVE-2026-12000

The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and

8.8
CVE-2026-70375

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDe

8.8
CVE-2026-70374

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail genera

7.5
CVE-2026-68073

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of

7.5
CVE-2026-67592

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

7.5
CVE-2026-67590

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of

7.5
CVE-2026-67552

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of

7.5
CVE-2026-66274

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of

7.5
CVE-2026-16736

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled sett

7.2
CVE-2026-16605

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to

7.5
CVE-2026-16604

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before

7.5
CVE-2026-16603

The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST

7.5
CVE-2026-16602

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an u

7.5
CVE-2026-16573

The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing un

7.5
CVE-2026-16561

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX action

7.5
CVE-2026-16055

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress au

7.5
CVE-2026-16036

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started