In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: fix stack out-of-bounds
In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: guard option walkers against 1
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_cthelper: fix OOB read in nfnl
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set
In the Linux kernel, the following vulnerability has been resolved: iavf: fix PTP use-after-free during reset Commit 7
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix physical SQE bounds check for SQE_MIX
In the Linux kernel, the following vulnerability has been resolved: net: bonding: Fix nd_tbl NULL dereference when IPv6
In the Linux kernel, the following vulnerability has been resolved: net/mana: Null service_wq on setup error to prevent
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Remove redundant css_put() in scx_cgroup
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: fix use-after-free on linked stream runt
In the Linux kernel, the following vulnerability has been resolved: rust_binder: check ownership before using vma When
In the Linux kernel, the following vulnerability has been resolved: rust_binder: avoid reading the written value in off
In the Linux kernel, the following vulnerability has been resolved: usb: class: cdc-wdm: fix reordering issue in read c
In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: fix use-after-free in ISR durin
In the Linux kernel, the following vulnerability has been resolved: ceph: add a bunch of missing ceph_path_info initial
In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_mo
In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for ns iteration io
In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for handle opening
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: clear walk_control on inactive conte
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix potential out-of-bounds rea
In the Linux kernel, the following vulnerability has been resolved: net: Fix rcu_tasks stall in threaded busypoll I wa
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/q54sj108a2) fix stack overflow in deb
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Don't log keys in SMB3 signing and encryptio
In the Linux kernel, the following vulnerability has been resolved: net: nexthop: fix percpu use-after-free in remove_n
In the Linux kernel, the following vulnerability has been resolved: net: ncsi: fix skb leak in error paths Early retur
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix use-after-free race in VM acquire
In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential overflow of shmem scatterli
In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: check if target buffer list is still
In the Linux kernel, the following vulnerability has been resolved: xfs: fix undersized l_iclog_roundoff values If the
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in
In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue Th
In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Or
Brave CMS is an open-source CMS. Prior to commit 6c56603, the contact form is publicly accessible (no authentication req
PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child proce
Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor ric
Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-u
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions
PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, reci
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonai
PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API
PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools
In the Linux kernel, the following vulnerability has been resolved: smb: client: require a full NFS mode SID before rea
In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: monaco: Reserve full Gunyah metad
In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix event ring index not programmed for I
In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UaF in addrconf_permanent_ad
In the Linux kernel, the following vulnerability has been resolved: lib/crypto: chacha: Zeroize permuted_state before i
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: force responder MITM requirements b
In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix thermal zone device registration
In the Linux kernel, the following vulnerability has been resolved: crypto: caam - fix overflow on long hmac keys When
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started