A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunky
React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability i
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on d
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bound accesses [WHAT &
In the Linux kernel, the following vulnerability has been resolved: mm: fix kernel BUG when userfaultfd_move encounters
In the Linux kernel, the following vulnerability has been resolved: mm/slab/kvfree_rcu: Switch to WQ_MEM_RECLAIM wq Cu
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel wiphy_work before freeing wi
In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Allow graceful removal of framebu
In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix kernel panic in the bnxt_get_queue_s
In the Linux kernel, the following vulnerability has been resolved: net: mctp: unshare packets when reassembling Ensur
In the Linux kernel, the following vulnerability has been resolved: net_sched: Prevent creation of classes with TC_H_RO
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Bridge, fix the crash caused by LAG state
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free Read in l
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix slab-use-after-free on hdcp_wo
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_free_work_struct
In the Linux kernel, the following vulnerability has been resolved: dm-flakey: Fix memory corruption in optional corrup
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Validate prev_cpu in scx_bpf_select_cpu_
In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix truesize for mb-xdp-pass case When
In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: do not update checksum in bnxt_xdp_build
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf
In the Linux kernel, the following vulnerability has been resolved: Revert "openvswitch: switch to per-action label cou
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent connection release during oplock bre
In the Linux kernel, the following vulnerability has been resolved: drivers: virt: acrn: hsm: Use kzalloc to avoid info
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Set hugetlb mmap base address aligned wi
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when u
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds in parse_sec_desc() If os
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_lock If smb_lock
In the Linux kernel, the following vulnerability has been resolved: drm/xe/hmm: Don't dereference struct page pointers
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix 'scheduling while atomic' in mptcp_pm_nl
In the Linux kernel, the following vulnerability has been resolved: rapidio: fix an API misues when rio_add_net() fails
In the Linux kernel, the following vulnerability has been resolved: mm: abort vma_modify() on merge out of memory failu
In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in hid
In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in ish
In the Linux kernel, the following vulnerability has been resolved: net: gso: fix ownership in __udp_gso_segment In __
In the Linux kernel, the following vulnerability has been resolved: net: hns3: make sure ptp clock is unregister and fr
In the Linux kernel, the following vulnerability has been resolved: HID: hid-steam: Fix use-after-free when detaching d
In the Linux kernel, the following vulnerability has been resolved: vlan: enforce underlying device type Currently, VL
In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in chil
In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show
In the Linux kernel, the following vulnerability has been resolved: slimbus: messaging: Free transaction ID in delayed
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: limit printed string from FW file T
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity T
In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a deadlock when recovering state on a si
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix bad hist from corrupting named_trigger
In the Linux kernel, the following vulnerability has been resolved: fuse: revert back to __readahead_folio() for readah
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems
Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui JSON Structuring Markup json-structuring-markup a
Cross-Site Request Forgery (CSRF) vulnerability in ProfitShare.ro WP Profitshare wp-profitshare allows Stored XSS.This i
Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader ebook-downloader allows Cross Site Reque
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started