In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: return NULL early from alloc_frozen_
In the Linux kernel, the following vulnerability has been resolved: vfio/cdx: Fix NULL pointer dereference in interrupt
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Triple fault if restore host CR3 fails o
In the Linux kernel, the following vulnerability has been resolved: EDAC/versalnet: Fix device_node leak in mc_probe()
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - snapshot IV for async AEAD req
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum number of lookups
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix damon_call() vs kdamond_fn() exi
In the Linux kernel, the following vulnerability has been resolved: dm mirror: fix integer overflow in create_dirty_log
In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix thermal zone governor cleanup is
In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-aes - Fix 3-page memory leak in atmel
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_
In the Linux kernel, the following vulnerability has been resolved: mm: fix deferred split queue races during migration
In the Linux kernel, the following vulnerability has been resolved: remoteproc: xlnx: Only access buffer information if
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Add missing save/restore handling of LBR
In the Linux kernel, the following vulnerability has been resolved: mm/memfd_luo: fix physical address conversion in pu
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix memory leaks in rxkad_verify_response()
In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-ntb: Remove duplicate resour
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix damos_walk() vs kdamond_fn() exi
In the Linux kernel, the following vulnerability has been resolved: hwmon: (powerz) Avoid cacheline sharing for DMA buf
In the Linux kernel, the following vulnerability has been resolved: xfs: fix a resource leak in xfs_alloc_buftarg() In
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the total number of nodes Cur
In the Linux kernel, the following vulnerability has been resolved: ext2: reject inodes with zero i_nlink and valid mod
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix conn-level packet handling to unshare RE
In the Linux kernel, the following vulnerability has been resolved: scsi: sd: fix missing put_disk() when device_add(&d
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add spectre boundry for syscall dispatch
In the Linux kernel, the following vulnerability has been resolved: slub: fix data loss and overflow in krealloc() Com
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Sync interrupt shadow to cached vmcb12 a
In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - fix a memory leak in cc_mac_digest(
In the Linux kernel, the following vulnerability has been resolved: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitt
In the Linux kernel, the following vulnerability has been resolved: nfsd: never defer requests during idmap lookup Dur
In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix NULL pointer dereference in acpi_ev_add
In the Linux kernel, the following vulnerability has been resolved: s390/cio: Fix device lifecycle handling in css_allo
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clean up the amdgpu_cs_parser_bos In l
In the Linux kernel, the following vulnerability has been resolved: staging: greybus: lights: avoid NULL deref gb_ligh
In the Linux kernel, the following vulnerability has been resolved: fbnic: close fw_log race between users and teardown
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix memory leak in amdgpu_ras_init() W
In the Linux kernel, the following vulnerability has been resolved: ublk: use READ_ONCE() to read struct ublksrv_ctrl_c
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid leaf access in btrfs_quota_enabl
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix UMR hang in LAG error state unload
In the Linux kernel, the following vulnerability has been resolved: bpf: Limit bpf program signature size Practical BP
In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Add missing check for input_ff_cr
In the Linux kernel, the following vulnerability has been resolved: cpuidle: Skip governor when only one idle state is
In the Linux kernel, the following vulnerability has been resolved: bpf: Return proper address for non-zero offsets in
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix NULL pointer dereference in __unix_ne
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix invalid deref of rawdata when export_
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gss_auth kref leak in gss_alloc_msg err
In the Linux kernel, the following vulnerability has been resolved: ASoC: nau8821: Cancel delayed work on component rem
In the Linux kernel, the following vulnerability has been resolved: ublk: Validate SQE128 flag before accessing the cmd
In the Linux kernel, the following vulnerability has been resolved: gfs2: fix memory leaks in gfs2_fill_super error pat
In the Linux kernel, the following vulnerability has been resolved: hfsplus: return error when node already exists in h
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started