In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: pcm512x: fix null-ptr dereference in
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Free private_irqs when init fails
In the Linux kernel, the following vulnerability has been resolved: fwctl: pds: Validate RPC input size before parsing
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix shrinker deadlock With PROVE_LOCKING
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid NULL-ptr deref for claim via
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: fix tp_vars reference leak in
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: avoid empty VLAN responses The com
In the Linux kernel, the following vulnerability has been resolved: irqchip/imgpdc: Fix resource leak, add missing chai
In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_new_modelist to prevent null-ptr-dere
In the Linux kernel, the following vulnerability has been resolved: nfsd: reset write verifier on deferred writeback er
In the Linux kernel, the following vulnerability has been resolved: vc_screen: fix null-ptr-deref in vcs_notifier() dur
In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer dereference in vidtv
In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error i
In the Linux kernel, the following vulnerability has been resolved: drm/colorop: Fix blob property reference tracking i
In the Linux kernel, the following vulnerability has been resolved: drm/msm: always recover the gpu Previously, in cas
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add upper bound check for num_of_nodes
A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain
In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: bound node_desc sysfs read with %.64s
In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Improve validation and configuratio
In the Linux kernel, the following vulnerability has been resolved: selinux: fix avdcache auditing The per-task avdcac
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings o
A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the fil
A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file ba
A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file ba
A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code o
A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManag
A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknow
A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAu
A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the compone
A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/das
A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/model
A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottl
A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _
A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of
A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file
A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMe
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the f
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of
A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file
The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the Woo
A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (l
Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the devic
A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/f
A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/e
A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spaw
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the f
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started