In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_acl/l
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iblock: Fix wrong PR ops NULL check f
In the Linux kernel, the following vulnerability has been resolved: mm/util: don't read __page_2 for order-1 folios in
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: give the socket its own sco_conn re
In the Linux kernel, the following vulnerability has been resolved: riscv/mm: use physical alignment for vmemmap_start_
In the Linux kernel, the following vulnerability has been resolved: i2c: amd-mp2: Unregister callback on adapter add fa
In the Linux kernel, the following vulnerability has been resolved: i2c: imx: Fix slave registration race and error han
In the Linux kernel, the following vulnerability has been resolved: driver core: use READ_ONCE() for dev->driver in dev
In the Linux kernel, the following vulnerability has been resolved: libbpf: Reject non-exclusive metadata maps in the s
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix u16 truncation of restart-area length che
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if kvm_translate_vncr()
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nat: reject unsupported target famili
In the Linux kernel, the following vulnerability has been resolved: tools/power/x86/intel-speed-select: Harden daemon p
In the Linux kernel, the following vulnerability has been resolved: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability
In the Linux kernel, the following vulnerability has been resolved: ufs: core: tracing: Do not dereference pointers in
In the Linux kernel, the following vulnerability has been resolved: hfsplus: Add a sanity check for btree node size Sy
In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Add slave_destroy interface for v3
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix OOB in scmi_power_name_get(
In the Linux kernel, the following vulnerability has been resolved: ipv6: guard against possible NULL deref in __in6_de
In the Linux kernel, the following vulnerability has been resolved: rapidio/tsi721: prevent a bad dereference in tsi721
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_remove_refc
In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: fix unaligned memory access in
In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from short trigger BA f
In the Linux kernel, the following vulnerability has been resolved: iommufd: Take dma_resv lock before dma_buf_unpin()
In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject compressed segment that overflow
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Serialize readq reset state with q-
In the Linux kernel, the following vulnerability has been resolved: char: tlclk: fix use-after-free in tlclk_cleanup()
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix potential UAF in aa_replace_profiles
In the Linux kernel, the following vulnerability has been resolved: net: dst_metadata: fix false-positive memcpy overfl
In the Linux kernel, the following vulnerability has been resolved: net: emac: Fix NULL pointer dereference in emac_pro
In the Linux kernel, the following vulnerability has been resolved: veth: fix NAPI leak in XDP enable error path Durin
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix iommu domain lifetime race durin
In the Linux kernel, the following vulnerability has been resolved: drm/xe/userptr: Hold notifier_lock for write on inj
In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix OOB read in hid_get_report for numbe
In the Linux kernel, the following vulnerability has been resolved: batman-adv: gw: acquire ethernet header only after
In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: ensure accessible eth_hdr proto fi
In the Linux kernel, the following vulnerability has been resolved: ntfs3: fix out-of-bounds read in decompress_lznt d
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - only expose sysfs attributes on co
In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus_atk0110) Check package count before ac
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix listxattr handling of corrupted xattr ent
In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its lo
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Script
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to,
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured im
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises use
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all vers
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started