In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer state for commuted arithmetic
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, return NULL on create error T
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix netns reference imbalance in conntrack kfu
In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: Fix use-after-free in bpf_iter_tcp_establ
In the Linux kernel, the following vulnerability has been resolved: vhost_iotlb: bound map allocation in add_range vho
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix type confusion in notification l
In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_X
In the Linux kernel, the following vulnerability has been resolved: xsk: validate launch-time metadata size Launch-tim
In the Linux kernel, the following vulnerability has been resolved: xsk: validate metadata when processing requests Th
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Validate T10 PI scatterlist counts Whe
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: reject feature changes after endpoint
In the Linux kernel, the following vulnerability has been resolved: net/openvswitch: check Ethernet header length in ke
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Always acquire rtnl_lock when d
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Disable EOP for TPA on all chips to preven
In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport m
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_flow_table: drop existing skb dst bef
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix TOCTOU race between smc_listen_out() a
In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before stoppi
In the Linux kernel, the following vulnerability has been resolved: s390/ism: Fix UAF of sba and ieq during ism_dev_exi
In the Linux kernel, the following vulnerability has been resolved: net/atm: fix slab-out-of-bounds read in vcc_setsock
In the Linux kernel, the following vulnerability has been resolved: watchdog: at91sam9_wdt: prevent timer rearm during
In the Linux kernel, the following vulnerability has been resolved: net: tap: set skb->dev before parsing virtio net he
In the Linux kernel, the following vulnerability has been resolved: net: usb: ax88179_178a: fix skb leak in ax88179_tx_
In the Linux kernel, the following vulnerability has been resolved: vt: stabilize tty reference in kbd_keycode with tty
In the Linux kernel, the following vulnerability has been resolved: mm: fix incorrect flush address in direct page tabl
In the Linux kernel, the following vulnerability has been resolved: ipvs: stop estimator after disabled calc phase IPV
In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in TX_RING s
In the Linux kernel, the following vulnerability has been resolved: net/packet: reset the MAC header on the packet-sock
In the Linux kernel, the following vulnerability has been resolved: packet: synchronize pressure clearing with ring rec
In the Linux kernel, the following vulnerability has been resolved: net/sched: reject overly deep qdisc hierarchies De
In the Linux kernel, the following vulnerability has been resolved: mac802154: fix netdev use-after-free in beacon work
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebt_nflog: pin the NFLOG backend nf_log
In the Linux kernel, the following vulnerability has been resolved: ipv4: fix use-after-free in fib_nhc_update_mtu() f
In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: fix TX DMA buffer flush When tr
In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: cancel RS485 hrtimers after fre
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie(
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix missing shared-key auth cha
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: validate monitor transmit frame
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Remove buffer from list prior to unm
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: take fl->lock when moving mmaps on i
In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: bound the hwdep mmap fault offset snd
In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: fix OOB write in fcp_meter_ctl_get() fc
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix group leader use-after-free after si
In the Linux kernel, the following vulnerability has been resolved: fbdev: bitblit: bound-check glyph index in bit_curs
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Prevent subbuf order change when resiz
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix huge_zero_pfn race Patch serie
In the Linux kernel, the following vulnerability has been resolved: net: smc: fix splice entry lifetime imbalance in sm
In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent in6_dev_get() from resurrecting inet6
In the Linux kernel, the following vulnerability has been resolved: net/dibs: Correct freeing of dmb_clientid_arr A di
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started