Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 94/1469
7.5
CVE-2026-18536

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource:

8.8
CVE-2026-16635

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0

8.1
CVE-2026-16144

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all

8.1
CVE-2026-15450

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path trav

7.2
CVE-2026-15052

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr

8.8
CVE-2026-15988

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request F

8.1
CVE-2026-15368

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after use

7.2
CVE-2026-15244

The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before con

7.5
CVE-2026-14839

The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public R

8.1
CVE-2026-14836

The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset

8.8
CVE-2026-14596

The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the

8.1
CVE-2026-14309

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been

7.1
CVE-2026-13725

The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user

7.2
CVE-2026-13158

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content impo

7.2
CVE-2026-13157

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import

8.8
CVE-2026-15414

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl

7.5
CVE-2026-15006

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln

8.0
CVE-2026-9044

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an

7.8
CVE-2026-34641

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co

7.4
CVE-2026-51953

An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication

7.1
CVE-2026-65981

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenti

8.8
CVE-2026-50986

PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment valid

7.2
CVE-2026-38710

TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock in

7.5
CVE-2026-62999

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-direc

7.5
CVE-2026-53599

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/s

8.1
CVE-2026-53510

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL

7.4
CVE-2026-18394

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to ob

7.5
CVE-2026-53505

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) fi

7.5
CVE-2026-53504

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expressio

7.5
CVE-2026-53503

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>,

8.2
CVE-2026-53501

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypasse

8.2
CVE-2026-53500

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes

7.3
CVE-2026-18481

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticate

7.3
CVE-2026-54737

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to

7.5
CVE-2026-52856

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a

8.2
CVE-2026-18141

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthentic

7.5
CVE-2026-17347

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that

8.8
CVE-2026-17346

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatin

7.5
CVE-2026-18446

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a refer

7.6
CVE-2026-10685

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked

7.5
CVE-2026-18358

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mo

8.1
CVE-2026-62391

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend

7.2
CVE-2026-16843

Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio

7.5
CVE-2026-15722

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function

7.5
CVE-2026-11770

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle

8.5
CVE-2026-10079

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, AC

8.1
CVE-2026-65313

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c

7.5
CVE-2026-65310

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu

7.5
CVE-2026-65309

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible form

8.8
CVE-2026-16236

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started