Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had comprom
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cro
Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker t
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re
Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compr
Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to lea
Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker t
Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to leak cross-o
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attac
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had co
Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap co
A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 t
A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the
A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function o
A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account
A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function
Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user t
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileg
Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Serv
A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/v
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Lea
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject empty multisync extension to preven
In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: fix error pointer dereference I
In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: Set vma_flags in vb2_dma_sg_mmap
In the Linux kernel, the following vulnerability has been resolved: media: renesas: vsp1: Fix NULL pointer deref on mod
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: os_dep: avoid NULL pointer dere
In the Linux kernel, the following vulnerability has been resolved: selinux: allow multiple opens of /sys/fs/selinux/po
In the Linux kernel, the following vulnerability has been resolved: pseries/papr-hvpipe: Fix race with interrupt handle
In the Linux kernel, the following vulnerability has been resolved: net: libwx: use request_irq for VF misc interrupt
In the Linux kernel, the following vulnerability has been resolved: spi: s3c64xx: fix NULL-deref on driver unbind A ch
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Do IRR scan in __kvm_apic_update_irr even
In the Linux kernel, the following vulnerability has been resolved: pmdomain: core: Fix detach procedure for virtual de
In the Linux kernel, the following vulnerability has been resolved: crypto: caam - guard HMAC key hex dumps in hash_dig
In the Linux kernel, the following vulnerability has been resolved: x86/efi: Fix graceful fault handling after FPU soft
In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix RTNL assertion warning when remove
In the Linux kernel, the following vulnerability has been resolved: leds: qcom-lpg: Check for array overflow when selec
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix early boot crash on parameters with
In the Linux kernel, the following vulnerability has been resolved: tpm: Use kfree_sensitive() to free auth session in
In the Linux kernel, the following vulnerability has been resolved: iio: frequency: admv1013: fix NULL pointer derefere
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix segfault when updating ftrace
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix zero-size GDS range init on RDNA4
fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to be
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines
OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory g
A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd48
A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Aff
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when cr
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to r
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started