In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: fix use-after-free on inexact bin in
In the Linux kernel, the following vulnerability has been resolved: net: add pskb_may_pull() to skb_gro_receive_list()
In the Linux kernel, the following vulnerability has been resolved: net: ibm: emac: Fix use-after-free during device re
In the Linux kernel, the following vulnerability has been resolved: netdev: fix double-free in netdev_nl_bind_rx_doit()
In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fai
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_T
In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX data at the hardware packet off
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix use-after-free on object
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Ann
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indi
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add buffer overflow check in MS get_inf
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC re
In the Linux kernel, the following vulnerability has been resolved: Revert "drm/xe: Skip exec queue schedule toggle if
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XN
In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: use kmap_local_page in netvsc_copy_to_se
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock o
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_
In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overfl
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Forcibly close timer instances at clos
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Fix UAF at snd_timer_user_params() At
In the Linux kernel, the following vulnerability has been resolved: io_uring/net: inherit IORING_CQE_F_BUF_MORE across
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: update file PMD counter before foli
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed in fops for ib_get_u
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate cpu_id against nr_cpu_ids in DM
In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial
In the Linux kernel, the following vulnerability has been resolved: udp: clear skb->dev before running a sockmap verdic
In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTCP co
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject oversized EMA RNR lists nl80
In the Linux kernel, the following vulnerability has been resolved: timers/migration: Fix livelock in tmigr_handle_remo
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix buffer over-read in rtw_upd
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks bef
In the Linux kernel, the following vulnerability has been resolved: ovl: keep err zero after successful ovl_cache_get()
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix OOB write in ethosu_gem_cmdstream
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix IFM region index out-of-bounds in
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix arithmetic issues in dma_length()
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialize
In the Linux kernel, the following vulnerability has been resolved: iomap: avoid potential null folio->mapping deref du
In the Linux kernel, the following vulnerability has been resolved: memcg: use round-robin victim selection in refill_s
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user i
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free race in fastrpc_m
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to fi
In the Linux kernel, the following vulnerability has been resolved: net: phonet: free phonet_device after RCU grace per
In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths
In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Clamp XDomain response data copy to al
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size b
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started