The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning p
The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing a
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it veri
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value be
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` v
In the Linux kernel, the following vulnerability has been resolved: sysfs: don't remove existing directory on update fa
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: call missing mem_cgroup_ite
In the Linux kernel, the following vulnerability has been resolved: efi: Allocate runtime workqueue before ACPI init S
In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: fix memory block reference lea
In the Linux kernel, the following vulnerability has been resolved: mm/memory_hotplug: fix memory block reference leak
In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: fix potential memory leaks in ipc_
In the Linux kernel, the following vulnerability has been resolved: phonet/pep: disable BH around forwarded sk_receive_
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: advance loop vars in cfg80211_merge
In the Linux kernel, the following vulnerability has been resolved: tracing: Do not call map->ops->elt_free() if elt_al
In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: fix pm_runtime leak on mutex_lock failu
In the Linux kernel, the following vulnerability has been resolved: spi: qup: fix error pointer deref after DMA setup f
In the Linux kernel, the following vulnerability has been resolved: spi: ep93xx: fix error pointer deref after DMA setu
In the Linux kernel, the following vulnerability has been resolved: spi: sprd: fix error pointer deref after DMA setup
In the Linux kernel, the following vulnerability has been resolved: kho: skip KHO for crash kernel kho_fill_kimage() u
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Check for NULL FF-A ID table whi
In the Linux kernel, the following vulnerability has been resolved: ARM: integrator: Fix early initialization Starting
In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: fix sleep while in atomic conte
In the Linux kernel, the following vulnerability has been resolved: test_kprobes: clear kprobes between test runs Runn
In the Linux kernel, the following vulnerability has been resolved: net: ti: icssm-prueth: fix eth_ports_node leak in p
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix zeropoint update where i_size > remote_i
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix partial invalidation of streaming-write
In the Linux kernel, the following vulnerability has been resolved: netfs, afs: Fix write skipping in dir/link writepag
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix error path leaks in some WMI WOW
In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: Fix a reference leak in a6xx_gpu_in
In the Linux kernel, the following vulnerability has been resolved: dma-mapping: move dma_map_resource() sanity check i
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix debugfs_lookup dentry leak and error
In the Linux kernel, the following vulnerability has been resolved: erofs: fix metabuf leak in inode xattr initializati
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: fix urb->setup_packet leak in err
In the Linux kernel, the following vulnerability has been resolved: platform/x86: uniwill-laptop: Do not enable the cha
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) widen blackbox-info buffer t
In the Linux kernel, the following vulnerability has been resolved: mm/memory: fix spurious warning when unmapping devi
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix initialization of tags of the hu
In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: fix spinlock leak in migrate_vma
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: drop ISO_END frames received withou
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: ecred_reconfigure: send packed pd
In the Linux kernel, the following vulnerability has been resolved: net: ethtool: fix NULL pointer dereference in phy_r
In the Linux kernel, the following vulnerability has been resolved: l2tp: use list_del_rcu in l2tp_session_unhash An u
In the Linux kernel, the following vulnerability has been resolved: igc: fix potential skb leak in igc_fpe_xmit_smd_fra
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started