In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE rpc
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply credit grant after par
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Repost Receive buffers for malformed repl
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race in unix socket mediation when pe
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix refcount leak when updating the sk_ct
In the Linux kernel, the following vulnerability has been resolved: apparmor: check label build before no_new_privs tes
In the Linux kernel, the following vulnerability has been resolved: apparmor: aa_label_alloc use aa_label_free on alloc
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix uninitialised pointer passed to audit
In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev(
In the Linux kernel, the following vulnerability has been resolved: drm/i915: clear CRTC color blob pointers after drop
In the Linux kernel, the following vulnerability has been resolved: xfrm: validate selector family and prefixlen during
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix list_del corruption in kfd_criu_res
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: qcom: reject stream disable with n
In the Linux kernel, the following vulnerability has been resolved: flow_dissector: check device type before reading ET
In the Linux kernel, the following vulnerability has been resolved: md/raid1: fix writes_pending and barrier reference
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending and barrier reference
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix order of kfree_rcu() and rcu_
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: make sure gc is properly stopped
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix effective prog array index with BPF_F_PREO
In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer spill metadata during half-sl
In the Linux kernel, the following vulnerability has been resolved: ice: fix FDIR CTRL VSI resource leak in ice_reset_a
In the Linux kernel, the following vulnerability has been resolved: bpf: Guard conntrack opts error writes The conntra
In the Linux kernel, the following vulnerability has been resolved: md/raid5: avoid R5_Overlap races while breaking str
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat: avoid invalid nat_net pointer us
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: prevent connlimit drops fo
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_compat: ebtables emulation must reje
In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Validate written enum value in ge_put_e
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mxl862xx: fix use-after-free of DSA ports
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Validate NIX maximum LFs correctly N
In the Linux kernel, the following vulnerability has been resolved: net: mvneta: re-enable percpu interrupt on resume
In the Linux kernel, the following vulnerability has been resolved: net: sungem: fix probe error cleanup gem_init_one(
In the Linux kernel, the following vulnerability has been resolved: net: udp_tunnel: prevent double queueing in udp_tun
In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in cleanup_bearer() due to premature
In the Linux kernel, the following vulnerability has been resolved: seg6: validate SRH length before reading fixed fiel
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) honor vrm_version in pmbus_data
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing events to regulator core
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_teql: Introduce slaves_lock to avoid
In the Linux kernel, the following vulnerability has been resolved: bridge: stp: Fix a potential use-after-free when de
In the Linux kernel, the following vulnerability has been resolved: sctp: fix addr_wq_timer race in sctp_free_addr_wq()
In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject undersized DACLs before parsing ACEs
In the Linux kernel, the following vulnerability has been resolved: xen/pvcalls: bound backend response req_id before i
In the Linux kernel, the following vulnerability has been resolved: afs: Fix error code in afs_extract_vl_addrs() The
In the Linux kernel, the following vulnerability has been resolved: afs: Fix reinitialisation of the inode, in particul
In the Linux kernel, the following vulnerability has been resolved: afs: Fix callback service message parsers to pass t
In the Linux kernel, the following vulnerability has been resolved: afs: Fix missing NULL pointer check in afs_break_so
In the Linux kernel, the following vulnerability has been resolved: afs: Fix lack of locking around modifications of ne
In the Linux kernel, the following vulnerability has been resolved: afs: Fix the volume AFS_VOLUME_RM_TREE is set on F
In the Linux kernel, the following vulnerability has been resolved: minix: avoid overflow in bitmap block count calcula
In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix double unlock in nomem_d_alloc erro
In the Linux kernel, the following vulnerability has been resolved: iomap: guard io_size EOF trim against concurrent tr
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started