Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 97/1469
7.5
CVE-2026-44107

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f

7.8
CVE-2026-44106

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to exec

7.8
CVE-2026-44099

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary

8.6
CVE-2026-44098

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to p

7.1
CVE-2026-44097

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for fi

7.8
CVE-2026-44096

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, re

7.8
CVE-2026-44095

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to ex

8.6
CVE-2026-44094

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configur

7.8
CVE-2026-44093

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user t

8.4
CVE-2026-58043

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

8.3
CVE-2026-47882

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foun

8.0
CVE-2026-47873

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network int

8.0
CVE-2026-47858

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicati

7.5
CVE-2026-16529

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU proce

7.3
CVE-2026-16527

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endp

8.8
CVE-2026-16526

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution

7.8
CVE-2026-16524

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.fil

7.5
CVE-2026-15240

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the oper

7.1
CVE-2026-14239

The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken fro

8.6
CVE-2026-13395

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a

7.5
CVE-2026-13178

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied

7.5
CVE-2026-12687

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th

7.5
CVE-2026-12500

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a

8.8
CVE-2026-67248

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because

8.1
CVE-2026-67245

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled

7.5
CVE-2026-1360

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ

8.8
CVE-2026-14356

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.

7.2
CVE-2026-67244

A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user

8.6
CVE-2026-48448

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL

8.1
CVE-2026-18188

A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled

8.1
CVE-2026-18187

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-control

8.1
CVE-2026-18186

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contr

8.8
CVE-2026-18017

Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insid

8.8
CVE-2026-18012

Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code ins

8.1
CVE-2026-17995

Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds

7.0
CVE-2026-17993

Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalat

8.8
CVE-2026-17989

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside

7.5
CVE-2026-17979

Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox

8.8
CVE-2026-17971

Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially p

8.8
CVE-2026-17969

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute a

8.8
CVE-2026-17967

Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially

8.8
CVE-2026-17956

Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute

7.5
CVE-2026-17952

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to i

8.8
CVE-2026-17951

Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bo

8.8
CVE-2026-17950

Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to

7.5
CVE-2026-17948

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malic

8.8
CVE-2026-17935

Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co

7.5
CVE-2026-17930

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack

8.8
CVE-2026-17922

Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute

8.8
CVE-2026-17920

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malic

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started