In the Linux kernel, the following vulnerability has been resolved: perf: Make sure to use pmu_ctx->pmu for groups Oli
In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use generic driver_override
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix undefined behavior in interpreter sdiv/smo
In the Linux kernel, the following vulnerability has been resolved: xfrm: prevent policy_hthresh.work from racing with
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix stack-out-of-bounds read in l
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix dangling pointer on mgmt_add_a
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Avoid releasing netdev before tea
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix double-free of smc_spd_priv when tee()
In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix double free of WoL irq We do not
In the Linux kernel, the following vulnerability has been resolved: iavf: fix out-of-bounds writes in iavf_get_ethtool_
In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_release() via NETDEV_
In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confusion with non-Ethern
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: serialize btintel_hw_error() wi
In the Linux kernel, the following vulnerability has been resolved: net: macb: use the current queue number for stats
In the Linux kernel, the following vulnerability has been resolved: RDMA/efa: Fix use of completion ctx after free On
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix use-after-free in migration restore
In the Linux kernel, the following vulnerability has been resolved: spi: meson-spicc: Fix double-put in remove path me
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not skip unrelated mode changes
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) Protect regulator operations wi
In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-lpspi: fix teardown order issue (UAF)
In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: fix OOB read in SQE_MIXED wrap che
In the Linux kernel, the following vulnerability has been resolved: drm/xe: always keep track of remap prev/next Durin
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leaks and NULL deref in smb2_lock
In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure Wh
In the Linux kernel, the following vulnerability has been resolved: ASoC: sma1307: fix double free of devm_kzalloc() me
In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix tx.buf use-after-free in isotp_send
In the Linux kernel, the following vulnerability has been resolved: media: mc, v4l2: serialize REINIT and REQBUFS with
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: only publish mode_data after clone set
In the Linux kernel, the following vulnerability has been resolved: virt: tdx-guest: Fix handling of host controlled 'q
In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RE
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Fix double free in dma-buf feature The e
In the Linux kernel, the following vulnerability has been resolved: erofs: add GFP_NOIO in the bio completion if needed
In the Linux kernel, the following vulnerability has been resolved: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_tar
In the Linux kernel, the following vulnerability has been resolved: xfs: stop reclaim before pushing AIL during unmount
In the Linux kernel, the following vulnerability has been resolved: xfs: save ailp before dropping the AIL lock in push
In the Linux kernel, the following vulnerability has been resolved: xfs: avoid dereferencing log items after push callb
In the Linux kernel, the following vulnerability has been resolved: ext4: convert inline data to extents when truncate
In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_ino
In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ext4_ext_correct_ind
In the Linux kernel, the following vulnerability has been resolved: ext4: reject mount if bigalloc with s_first_data_bl
In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in update_super_work when
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible invalid memory access
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under cer
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggre
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handl
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Ext
The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound req
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started