In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dsc eDP issue [why] Need to a
In the Linux kernel, the following vulnerability has been resolved: spi: spidev: fix lock inversion between spi_lock an
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix sync handling in amdgpu_dma_buf_mov
In the Linux kernel, the following vulnerability has been resolved: most: core: fix leak on early registration failure
In the Linux kernel, the following vulnerability has been resolved: media: solo6x10: Check for out of bounds chip_id C
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Remove a user-triggerable WARN on nested
In the Linux kernel, the following vulnerability has been resolved: dm: remove fake timeout to avoid leak request Sinc
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix NULL-pointer dereference in ac
In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Initialize subdev before contro
In the Linux kernel, the following vulnerability has been resolved: soc/tegra: pmc: Fix unsafe generic_handle_irq() cal
In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: Avoid G2 bus error while decodi
In the Linux kernel, the following vulnerability has been resolved: md raid: fix hang when stopping arrays with metadat
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't BUG() on unexpected delayed ref type i
In the Linux kernel, the following vulnerability has been resolved: bpf: crypto: Use the correct destructor kfunc type
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix mismatched unlock for DMUB HW
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Set DMA segment size to avoid debug warnin
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix PM runtime usage cou
In the Linux kernel, the following vulnerability has been resolved: drm/panel: Fix a possible null-pointer dereference
In the Linux kernel, the following vulnerability has been resolved: btrfs: do not ASSERT() when the fs flips RO inside
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Skip vcn poison irq release on VF VF d
In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rga: Fix possible ERR_PTR derefere
In the Linux kernel, the following vulnerability has been resolved: rapidio: replace rio_free_net() with kfree() in rio
In the Linux kernel, the following vulnerability has been resolved: drm: renesas: rz-du: mipi_dsi: fix kernel panic whe
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix kthread worker destr
In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: prevent RCU stalls in kasan_release_vma
In the Linux kernel, the following vulnerability has been resolved: kexec: derive purgatory entry from symbol kexec_lo
In the Linux kernel, the following vulnerability has been resolved: ext4: move ext4_percpu_param_init() before ext4_mb_
In the Linux kernel, the following vulnerability has been resolved: drm: Account property blob allocations to memcg DR
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: restore failed global reservations to s
In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not access current->mems_allowed_seq if
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-gi
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version
In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap
In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the
In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madv
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_confi
In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purg
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id'
The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom pos
The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entr
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started