In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: drain a slave's callback before its ma
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: don't re-enter an instance callback th
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB access from firmware ADDBA wi
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_stat
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: validate assoc response length befo
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: make release_scratchbuffers idempot
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UUID list traversal T
In the Linux kernel, the following vulnerability has been resolved: misc: nsm: only unlock nsm_dev on post-lock error p
In the Linux kernel, the following vulnerability has been resolved: misc: nsm: pin the module while the device is open
In the Linux kernel, the following vulnerability has been resolved: tracing: Delay module ref count for "enable_event"
In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready() instead of ub->compl
In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handled unaligned address
In the Linux kernel, the following vulnerability has been resolved: mm/page_vma_mapped: fix device-private PMD handling
In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns tea
In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Loca
In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors
In the Linux kernel, the following vulnerability has been resolved: libceph: remove debugfs files before client teardow
In the Linux kernel, the following vulnerability has been resolved: amt: fix use-after-free in AMT delayed works When
In the Linux kernel, the following vulnerability has been resolved: fs: preserve ACL_DONT_CACHE state in forget_cached_
In the Linux kernel, the following vulnerability has been resolved: fscrypt: Add missing superblock check in find_or_in
In the Linux kernel, the following vulnerability has been resolved: fscrypt: Avoid dynamic allocation in fscrypt_get_de
In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-len
In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer realloc
In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device netns f
In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in afiucv_hs_callback_s
In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv_path
In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concur
In the Linux kernel, the following vulnerability has been resolved: ptp: ptp_s390: Add missing facility check Only reg
In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result codes to zero in object
In the Linux kernel, the following vulnerability has been resolved: gve: fix Rx queue stall on alloc failure When the
In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profil
In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the au
In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header(
In the Linux kernel, the following vulnerability has been resolved: rtase: Workaround for TX hang caused by hardware pa
In the Linux kernel, the following vulnerability has been resolved: tcp: initialize standalone TCP-AO response padding
In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVE
In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix source list corruption on a failed
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length R
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix division by zero with invalid uvd d
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_remove() before freeing
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject mapping a reserved doorbell to a
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set
In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_nt
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authoritie
In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking deadlock in audit_dupe
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem`
Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. T
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start probe fa
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when wr
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started