In the Linux kernel, the following vulnerability has been resolved: sched/rt: Have RT_PUSH_IPI be default off for non P
In the Linux kernel, the following vulnerability has been resolved: cpufreq: pcc: fix use-after-free and double free in
In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not limit zeroing to orig_size when onl
In the Linux kernel, the following vulnerability has been resolved: HID: hid-goodix-spi: validate report size to preven
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix slab-out-of-bounds write in wacom_w
In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access on mt
In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: fix u32 overflow in check_and_correct_
In the Linux kernel, the following vulnerability has been resolved: bpf: Validate BTF repeated field counts before expa
In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corr
In the Linux kernel, the following vulnerability has been resolved: udf: validate free block extents against the partit
In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT ino
In the Linux kernel, the following vulnerability has been resolved: udf: validate sparing table length as an entry coun
In the Linux kernel, the following vulnerability has been resolved: partitions: aix: bound the pp_count scan to the ppe
In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink components to the S
In the Linux kernel, the following vulnerability has been resolved: crypto: caam - use print_hex_dump_devel to guard ke
In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplicat
In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - restore callback for non-parallel
In the Linux kernel, the following vulnerability has been resolved: crypto: loongson - Remove broken and unused loongso
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths T
In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix page UAF in map_range() map_range()
In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent out-of-bounds read in glob matchin
In the Linux kernel, the following vulnerability has been resolved: NFSv4: include MAY_WRITE in open permission mask fo
In the Linux kernel, the following vulnerability has been resolved: exfat: bound uniname advance in exfat_find_dir_entr
In the Linux kernel, the following vulnerability has been resolved: iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM h
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Clear __hyp_running_vcpu when flushing
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure vendor's exit handler runs before
In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Treat memslot binding offset+size
In the Linux kernel, the following vulnerability has been resolved: svcrdma: wake sq waiters when the transport closes
In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_d
In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter deregistration race Adapter
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the
In the Linux kernel, the following vulnerability has been resolved: Input: goodix - clamp the device-reported contact c
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - bound the device-reported force-fee
In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - fix touch indexing for MMS134S and
In the Linux kernel, the following vulnerability has been resolved: Input: touchwin - reset the packet index on every c
In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - reject an oversized device packet s
In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before returning from fuse_re
In the Linux kernel, the following vulnerability has been resolved: fuse: clear intr_entry in fuse_resend and fuse_remo
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-free in fuse_uring_asyn
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid queue->stopped races and set/read
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only find
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc fil
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started