In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: Fix reference leak in amdgpu_user
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add upper bound check on user inputs in
In the Linux kernel, the following vulnerability has been resolved: drm/bridge: samsung-dsim: Fix memory leak in error
In the Linux kernel, the following vulnerability has been resolved: drm/xe/sync: Fix user fence leak on alloc failure
In the Linux kernel, the following vulnerability has been resolved: drm/xe/sync: Cleanup partially initialized sync on
In the Linux kernel, the following vulnerability has been resolved: nfsd: Fix cred ref leak in nfsd_nl_listener_set_doi
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix chunk map leak in btrfs_map_block() afte
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix starvation of scx_enable() under fai
In the Linux kernel, the following vulnerability has been resolved: nstree: tighten permission checks for listing Even
In the Linux kernel, the following vulnerability has been resolved: mm: memfd_luo: always dirty all folios A dirty fol
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: properly validate the data in r
In the Linux kernel, the following vulnerability has been resolved: batman-adv: Avoid double-rtnl_lock ELP metric worke
In the Linux kernel, the following vulnerability has been resolved: nouveau/dpcd: return EBUSY for aux xfer if the devi
In the Linux kernel, the following vulnerability has been resolved: net: mctp: fix device leak on probe failure Driver
In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Fix error path in PTP IRQ setu
In the Linux kernel, the following vulnerability has been resolved: net: macb: Shuffle the tx ring before enabling tx
In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix NULL pointer dereference in device cle
In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix a few more NULL pointer dereference in
In the Linux kernel, the following vulnerability has been resolved: ublk: fix NULL pointer dereference in ublk_ctrl_set
In the Linux kernel, the following vulnerability has been resolved: x86/apic: Disable x2apic on resume if the kernel ex
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction abort when snapshotting rece
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction abort on file creation due t
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction abort on set received ioctl
In the Linux kernel, the following vulnerability has been resolved: btrfs: add missing RCU unlock in error path in try_
In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050-core: fix pm_runtime error handl
In the Linux kernel, the following vulnerability has been resolved: iio: imu: adis: Fix NULL pointer dereference in adi
In the Linux kernel, the following vulnerability has been resolved: iio: light: bh1780: fix PM runtime leak on error pa
In the Linux kernel, the following vulnerability has been resolved: iio: proximity: hx9023s: Protect against division b
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Eagerly init vgic dist/redist on vgic c
ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1
In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was ident
Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, the
Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.
PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI exposes optional SQL/CQL
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid uninit-value access in f2fs_sani
In the Linux kernel, the following vulnerability has been resolved: mshv_vtl: Fix vmemmap_shift exceeding MAX_FOLIO_ORD
In the Linux kernel, the following vulnerability has been resolved: ice: ptp: don't WARN when controlling PF is unavail
In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Fix die ID init and look up
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_subset: Fix unbalanced refcnt in get
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Protect RNDIS options with mu
In the Linux kernel, the following vulnerability has been resolved: comedi: Reinit dev->spinlock between attachments to
In the Linux kernel, the following vulnerability has been resolved: btrfs: reserve enough transaction items for qgroup
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL pointer dereference in dc
In the Linux kernel, the following vulnerability has been resolved: interconnect: qcom: sm8450: Fix NULL pointer derefe
In the Linux kernel, the following vulnerability has been resolved: bpf: reject direct access to nullable PTR_TO_BUF po
In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_
In the Linux kernel, the following vulnerability has been resolved: USB: dummy-hcd: Fix locking/synchronization error
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix SCX_KICK_WAIT deadlock by deferring
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't send a 6E related command
In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix zero_vruntime tracking fix John re
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started