In the Linux kernel, the following vulnerability has been resolved: batman-adv: avoid OGM aggregation when skb tailroom
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free u
In the Linux kernel, the following vulnerability has been resolved: openvswitch: validate MPLS set/set_masked payload l
In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release
In the Linux kernel, the following vulnerability has been resolved: rxrpc: only handle RESPONSE during service challeng
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in p
In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rt: reject oversized addrnr in rt_m
In the Linux kernel, the following vulnerability has been resolved: af_unix: read UNIX_DIAG_VFS data under unix_state_l
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of
Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and ex
Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's c
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to befo
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr
uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buf
SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messa
4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer
Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.ym
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influe
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively wal
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadg
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFin
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists
rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() co
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::deriv
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-
Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in
Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed e
In the Linux kernel, the following vulnerability has been resolved: Input: uinput - fix circular locking dependency wit
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix incorrect return value after changing le
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-after-free in timeout ob
In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_
In the Linux kernel, the following vulnerability has been resolved: tipc: fix bc_ackers underflow on duplicate GRP_ACK_
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: fix refcount underflow in intel_engine
In the Linux kernel, the following vulnerability has been resolved: mm/damon/stat: deallocate damon_call() failure leak
In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free on disconnect The
In the Linux kernel, the following vulnerability has been resolved: mm: filemap: fix nr_pages calculation overflow in f
In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix use-after-free and leak in lan966
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrp
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix use of wrong skb when comparing queued R
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Only put the call ref if one was acquired r
In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started