In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF in binder_thread_release() When a
In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF in binder_free_transaction() In bi
In the Linux kernel, the following vulnerability has been resolved: rust_binder: use a u64 stride when cleaning up the
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci_rt1711h: unregister TCPCI port wi
In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Skip VF Resizable BAR restore on read erro
In the Linux kernel, the following vulnerability has been resolved: hwrng: virtio: clamp device-reported used.len at co
In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix NHC entry use-after-free on error path
In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: bound slave read/write to the ke
In the Linux kernel, the following vulnerability has been resolved: smb: client: restrict implied bcc[0] exemption to r
In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix double-free and use-after
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow and OO
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_i
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in is
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handle
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in adf_d
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock o
In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp stat
In the Linux kernel, the following vulnerability has been resolved: audit: Fix data races of skb_queue_len() readers on
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout by hol
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate Dirty Page Table capacity in log
In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid calling post_write_mst_fixup() for inva
In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid calling pci_irq_vector() from hardi
In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: remove multicast group from hash table
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and M
In the Linux kernel, the following vulnerability has been resolved: mfd: cros_ec: Delay dev_set_drvdata() until probe s
In the Linux kernel, the following vulnerability has been resolved: mm: shrinker: fix shrinker_info teardown race with
In the Linux kernel, the following vulnerability has been resolved: netfilter: handle unreadable frags sashiko reports
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-term
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before fi
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accep
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before rea
In the Linux kernel, the following vulnerability has been resolved: coresight: ultrasoc-smb: Fix OOB write in smb_sync_
In the Linux kernel, the following vulnerability has been resolved: smb: client: resolve SWN tcon from live registratio
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DA
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOCK def
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require source read access for duplicate ext
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SE
In the Linux kernel, the following vulnerability has been resolved: ksmbd: track the connection owning a byte-range loc
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating ses
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix chown/chgrp with SMB3 POSIX Extensi
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay
In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix
In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 07777 in
In the Linux kernel, the following vulnerability has been resolved: writeback: fix race between cgroup_writeback_umount
In the Linux kernel, the following vulnerability has been resolved: proc: protect ptrace_may_access() with exec_update_
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started