In the Linux kernel, the following vulnerability has been resolved: selinux: avoid sk_socket dereference in selinux_sct
In the Linux kernel, the following vulnerability has been resolved: batman-adv: retrieve ethhdr after potential skb rea
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: reacquire gw address after skb rea
In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ethernet header on TX A
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: avoid request storms during pending
In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: avoid OOB read of num_dests head
In the Linux kernel, the following vulnerability has been resolved: jbd2: fix integer underflow in jbd2_journal_initial
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge
In the Linux kernel, the following vulnerability has been resolved: ntfs: centalize $INDEX_ROOT header validation Add
In the Linux kernel, the following vulnerability has been resolved: ntfs: skip extent mft records in writeback to preve
In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid heap allocation for free-cluster readah
In the Linux kernel, the following vulnerability has been resolved: ntfs: reject non-resident records for resident-only
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound DeleteIndexEntryAllocation memmove
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound copy_lcns dp->page_lcns[] index in
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound attr_off in UpdateResidentValue aga
In the Linux kernel, the following vulnerability has been resolved: landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the S
In the Linux kernel, the following vulnerability has been resolved: mips: sched: Fix CPUMASK_OFFSTACK memory corruption
In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-
In the Linux kernel, the following vulnerability has been resolved: mm/mm_init: fix uninitialized struct pages for ZONE
In the Linux kernel, the following vulnerability has been resolved: mtd: slram: remove failed entries from the device l
In the Linux kernel, the following vulnerability has been resolved: 9p: skip nlink update in cacheless mode to fix WARN
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix condition in 'nand_select_target(
In the Linux kernel, the following vulnerability has been resolved: ocfs2: avoid moving extents to occupied clusters F
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2
In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject dinodes with non-canonical i_mode typ
In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Fix frags[] overflow by bounding
In the Linux kernel, the following vulnerability has been resolved: openrisc: Fix jump_label smp syncing The original
In the Linux kernel, the following vulnerability has been resolved: tpm: tpm2-sessions: wait for async KPP completion i
In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra: Fix burst size calculation Curre
In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Add spinlock to protect DONE_IN
In the Linux kernel, the following vulnerability has been resolved: dmaengine: sh: rz-dmac: Move interrupt request afte
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-laptop: fix missing cleanups in
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Restore SST-PP control to all d
In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix locked bus on SMBus block-read of 0 (
In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_interface: require CAP_NET_ADMIN in the
In the Linux kernel, the following vulnerability has been resolved: tpm: Make the TPM character devices non-seekable T
In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO when DMA cannot be st
In the Linux kernel, the following vulnerability has been resolved: spi: uniphier: Fix completion initialization order
In the Linux kernel, the following vulnerability has been resolved: can: isotp: use unconditional synchronize_rcu() in
In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix use-after-free race with concurrent
In the Linux kernel, the following vulnerability has been resolved: can: isotp: serialize TX state transitions under so
In the Linux kernel, the following vulnerability has been resolved: can: bcm: defer rx_op deallocation to workqueue to
In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix lockless bound/ifindex race and silen
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking when updating filter and time
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu list annotations and oper
In the Linux kernel, the following vulnerability has been resolved: can: bcm: extend bcm_tx_lock usage for data and tim
In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops after device removal
In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDE
In the Linux kernel, the following vulnerability has been resolved: can: bcm: validate frame length in bcm_rx_setup() f
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing device refcount for CAN filte
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started