In the Linux kernel, the following vulnerability has been resolved: qede: sync udp_tunnel ports outside qede_lock in th
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __close_file_table_ids
In the Linux kernel, the following vulnerability has been resolved: iommu/iommufd: Fix IOPF group ownership UAF iopf_g
In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: don't free uninitialized dev_n
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix list corruption in allocate_file_re
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Update x2APIC MSR intercepts if AVIC is i
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Reject adapter interrupt forwarding
In the Linux kernel, the following vulnerability has been resolved: dibs: fix use-after-free of dmb_node in loopback at
In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-free in audit_del_ru
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix UAF in pair command cancellati
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix advertising data UAFs hci
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames without a transactio
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payloads
In the Linux kernel, the following vulnerability has been resolved: afs: Fix UAF when sending a message In afs_make_ca
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the c
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame size in implicit-feedb
In the Linux kernel, the following vulnerability has been resolved: fou: Fix use-after-free in fou_create() fou_create
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: do not update comments from kerne
In the Linux kernel, the following vulnerability has been resolved: tipc: avoid use-after-free in poll trace queue dump
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix tid_tx use-after-free on BA ses
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: use the subframe length when parsing
In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: reject a flag character as the field d
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: unlock i_mmap_rwsem before releasin
In the Linux kernel, the following vulnerability has been resolved: mm/page_reporting: use system_freezable_wq to fix U
In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix proc entry use-after-free pktgen_
In the Linux kernel, the following vulnerability has been resolved: tracing: Check return value of __register_event() i
In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZONES alloc_len underf
In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_a
In the Linux kernel, the following vulnerability has been resolved: s390/qeth: Check CAP_NET_ADMIN for private ioctls
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix potential UAF on meter attach
In the Linux kernel, the following vulnerability has been resolved: i2c: imx: Cancel hrtimer before clearing slave poin
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: peak_usb_start(): fix double free of
In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Supply the overflow slot size in BPOS, not
In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Zero the tile state data array before each
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: reject firmware sections with oversize
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: validate firmware interface structure
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix pptable use-after-free amdgpu_dpm_
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix divide-by-zero in calculate_mc
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix uint32_t overflow in EOP ring buffe
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: hold event_mutex while checkpointing CR
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate DRAW_PRIMITIVES header size be
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: bound DMA command body size against suf
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Wait on external BO kernel fences in exec I
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured,
Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Con
The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPres
The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2
In the Linux kernel, the following vulnerability has been resolved: crypto: sun4i-ss - Remove insecure and unused rng_a
In the Linux kernel, the following vulnerability has been resolved: rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started