In the Linux kernel, the following vulnerability has been resolved: ovpn: fix use after free in unlock_ovpn() unlock_o
In the Linux kernel, the following vulnerability has been resolved: hwmon: occ: validate poll response sensor blocks T
In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after
In the Linux kernel, the following vulnerability has been resolved: rds: drop incoming messages that cross network name
In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix DMA direction for NPU mailbox buff
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Wait for completion instead of returning
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound uAP association event IEs to t
In the Linux kernel, the following vulnerability has been resolved: tipc: serialize udp bearer replicast list updates
In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_au
In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Fix element size accounting for cmd
In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strrese
In the Linux kernel, the following vulnerability has been resolved: net: mctp i3c: clean up notifier and buses if drive
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Add drm_dev guards when detaching CCS re
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Ge
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Fix SVM leak on resv obj alloc failure i
In the Linux kernel, the following vulnerability has been resolved: tipc: fix u16 MTU truncation in media and bearer MT
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Zero-extend signed ALU32 div/mod re
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 d
In the Linux kernel, the following vulnerability has been resolved: rds: tcp: unregister sysctl before tearing down lis
In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attr
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_se
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free freeing trigger private
In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix buffer overflow in steered register
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix context pstate override handling T
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Reset current_op in xe_pt_update_ops_ini
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix double call to drm_sched_entit
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix user array stride in pvr_set_u
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: acquire vm_ctx->lock before mappin
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue type
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix 32-bit overflow in CWSR total size
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: bound EDID block reads to the response
In the Linux kernel, the following vulnerability has been resolved: drm/i915/hdcp: check streams[] bounds before overfl
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix lifetime issue of amdgpu_vm_get_tas
In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: publish dpagemap early to avoid device
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: set new_stream to NULL after relea
In the Linux kernel, the following vulnerability has been resolved: media: amlogic-c3: Add validations for ae and awb c
In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference list en
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Move src_buf Removal to
In the Linux kernel, the following vulnerability has been resolved: media: msi2500: Return queued buffers on start_stre
In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Fix potential out-of-bounds i
In the Linux kernel, the following vulnerability has been resolved: media: pwc: Return queued buffers on start_streamin
In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: Return queued buffers on start_
In the Linux kernel, the following vulnerability has been resolved: media: stm32: dcmi: unregister notifier on probe fa
In the Linux kernel, the following vulnerability has been resolved: media: sun4i-csi: Return queued buffers on start_st
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC active reference c
In the Linux kernel, the following vulnerability has been resolved: media: vivid: check for vb2_is_busy() when toggling
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: close a re-opened queue timer in the des
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started