In the Linux kernel, the following vulnerability has been resolved: io_uring/bpf-ops: reject re-registration of an alre
In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register bounds before narrowing retval
In the Linux kernel, the following vulnerability has been resolved: bpf,fork: wipe ->bpf_storage before bailouts that a
In the Linux kernel, the following vulnerability has been resolved: net: sparx5: unregister blocking notifier on init f
In the Linux kernel, the following vulnerability has been resolved: dm thin metadata: fix metadata snapshot consistency
In the Linux kernel, the following vulnerability has been resolved: dm era: fix out-of-bounds memory access for non-zer
In the Linux kernel, the following vulnerability has been resolved: dm-log: fix a bitset_size overflow on 32bit machine
In the Linux kernel, the following vulnerability has been resolved: dm: avoid leaking the caller's thread keyring via t
In the Linux kernel, the following vulnerability has been resolved: dm_early_create: fix freeing used table on dm_resum
In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix a bug if the bio is out of limits
In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twice ha
In the Linux kernel, the following vulnerability has been resolved: dma-fence: Make dma_fence_dedup_array() robust agai
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix use-after-free in amdxdna_gem_dm
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Use caller client for debug BO sync
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Reject firmware log with size smaller t
In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix use-after-free during unmount Duri
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: macsec: fix use-after-free of metadata_d
In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Fix use-after-free in user_eve
In the Linux kernel, the following vulnerability has been resolved: cpu: hotplug: Preserve per instance callback errors
In the Linux kernel, the following vulnerability has been resolved: cpu: hotplug: Bound hotplug states sysfs output st
In the Linux kernel, the following vulnerability has been resolved: net: sit: require CAP_NET_ADMIN in the device netns
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: preserve tc_skb_cb across defrag
In the Linux kernel, the following vulnerability has been resolved: net: ip6_vti: require CAP_NET_ADMIN in the device n
In the Linux kernel, the following vulnerability has been resolved: net: ip_vti: require CAP_NET_ADMIN in the device ne
In the Linux kernel, the following vulnerability has been resolved: net: ipip: require CAP_NET_ADMIN in the device netn
In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN in the device n
In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET_ADMIN in the devic
In the Linux kernel, the following vulnerability has been resolved: ieee802154: admin-gate legacy LLSEC dump operations
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing dirty page tracking in {pte,
In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix user refcount underflow in event delivery
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_multiq: Replace direct dequeue call
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_taprio: Replace direct dequeue call
In the Linux kernel, the following vulnerability has been resolved: fhandle: reject detached mounts in capable_wrt_moun
In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: bound device offsets in the MUX do
In the Linux kernel, the following vulnerability has been resolved: mm/compaction: handle free_pages_prepare() properly
In the Linux kernel, the following vulnerability has been resolved: mac802154: remove interfaces with RCU list deletion
In the Linux kernel, the following vulnerability has been resolved: ipvs: use parsed transport offset in SCTP state loo
In the Linux kernel, the following vulnerability has been resolved: macsec: don't read an unset MAC header in macsec_en
In the Linux kernel, the following vulnerability has been resolved: dibs: loopback: validate offset and size in move_da
In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Call synchronize_rcu() when unregi
In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: Extract PHY as shared dom
In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: avoid full teardown before work setup
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a short a
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: validate firmware patch bounds r
In the Linux kernel, the following vulnerability has been resolved: powerpc/spufs: fix out-of-bounds access in spufs_me
In the Linux kernel, the following vulnerability has been resolved: powerpc/uaccess: correct check for CONFIG_PPC_E500
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate EHT MLE before MLD ID read
In the Linux kernel, the following vulnerability has been resolved: wifi: ieee80211: validate MLE common info length i
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate extension-frame layout bef
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started