In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: fix race conditions in sco_sock_con
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate LTK enc_size on load Loa
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in set_cig_p
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_r
In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: Fix use-after-free of sk->sk_socket i
In the Linux kernel, the following vulnerability has been resolved: net: macb: fix clk handling on PCI glue driver remo
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix incorrect pruning due to atomic fetch prec
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Handle DBC deactivation if the owner we
In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: reject zero-length fixed buffer impo
In the Linux kernel, the following vulnerability has been resolved: hwmon: (tps53679) Fix array access with zero-length
An issue was discovered in VrmlData_IndexedFaceSet::TShape in the VRML V2.0 parser in Open CASCADE Technology (OCCT) V8_
A heap-based out-of-bounds read vulnerability in RWObj_Reader::read in the OBJ file parser in Open CASCADE Technology (O
Two heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser in Open CASCADE Technology (OCCT) V8_0_0_
In the Linux kernel, the following vulnerability has been resolved: perf/x86: Fix potential bad container_of in intel_p
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix u8 overflow in SSID scan buffer
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds rea
In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: fix stack out-of-bounds read in init_c
In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix missing SPDIFI1 index handling SP
In the Linux kernel, the following vulnerability has been resolved: io_uring/net: fix slab-out-of-bounds read in io_bun
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: derive legacy responder STK authent
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix stack buffer overflow in h
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: move wake reason storage into
In the Linux kernel, the following vulnerability has been resolved: gpib: fix use-after-free in IO ioctl handlers The
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-adc161s626: use DMA-safe memory for sp
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate doorbell_offset in user queue
In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: Set buffer sampling frequency
In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Move iio_device_register() to c
In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix double free in ulpi_register_interfa
In the Linux kernel, the following vulnerability has been resolved: usb: usbtmc: Flush anchored URBs in usbtmc_release
In the Linux kernel, the following vulnerability has been resolved: comedi: me_daq: Fix potential overrun of firmware b
In the Linux kernel, the following vulnerability has been resolved: comedi: me4000: Fix potential overrun of firmware b
In the Linux kernel, the following vulnerability has been resolved: reset: gpio: fix double free in reset_add_gpio_aux_
In the Linux kernel, the following vulnerability has been resolved: nvmem: zynqmp_nvmem: Fix buffer size in DMA and mem
In the Linux kernel, the following vulnerability has been resolved: vt: discard stale unicode buffer on alt screen exit
In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Add missing CRYPTO_ALG_ASYNC The t
In the Linux kernel, the following vulnerability has been resolved: iommupt: Fix short gather if the unmap goes into a
In the Linux kernel, the following vulnerability has been resolved: thermal: core: Address thermal zone removal races w
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: possible double-free of cctx->remote
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: validate control reques
In the Linux kernel, the following vulnerability has been resolved: crypto: krb5enc - fix async decrypt skipping hash v
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate owner of durable handle on reconnec
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate rec->used in journal-replay file
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix UAF caused by decrementing sbi->nr_pages[
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require minimum ACE size in smb_check_perm_d
In the Linux kernel, the following vulnerability has been resolved: smb: server: fix active_num_conn leak on transport
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriti
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate response sizes in ipc_validate_msg(
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_aces and harden ACE walk in smb
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started