In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Skip dev-iotlb flush for inaccessible P
In the Linux kernel, the following vulnerability has been resolved: mfd: macsmc: Initialize mutex Initialize struct ap
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix null dereference in find_ne
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: CGX: fix bitmap leaks The RX/TX flow
In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: enable basic endpoint checking
In the Linux kernel, the following vulnerability has been resolved: mux: mmio: fix regmap leak on probe failure The mm
In the Linux kernel, the following vulnerability has been resolved: erofs: fix incorrect early exits in volume label ha
In the Linux kernel, the following vulnerability has been resolved: HID: hid-pl: handle probe errors Errors in init mu
In the Linux kernel, the following vulnerability has been resolved: Revert "media: iris: Add sanity check for stop stre
In the Linux kernel, the following vulnerability has been resolved: net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in u
In the Linux kernel, the following vulnerability has been resolved: powerpc/smp: Add check for kcalloc() failure in par
In the Linux kernel, the following vulnerability has been resolved: Revert "PCI/IOV: Add PCI rescan-remove locking when
In the Linux kernel, the following vulnerability has been resolved: media: iris: Add buffer to list only after successf
In the Linux kernel, the following vulnerability has been resolved: remoteproc: imx_rproc: Fix invalid loaded resource
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential kernel oops when prob
In the Linux kernel, the following vulnerability has been resolved: mfd: core: Add locking around 'mfd_of_node_list' M
In the Linux kernel, the following vulnerability has been resolved: media: iris: gen1: Destroy internal buffers after F
In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: Do not crash on missing msc->input
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Fix NULL pointer dereference
In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Check maxfield in hidpp_get_re
In the Linux kernel, the following vulnerability has been resolved: media: cx23885: Add missing unmap in snd_cx23885_hw
In the Linux kernel, the following vulnerability has been resolved: dm-verity: correctly handle dm_bufio_client_create(
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Fix null pointer dereference issue If
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Flush dev-IOTLB only when PCIe device i
In the Linux kernel, the following vulnerability has been resolved: ima: verify the previous kernel's IMA buffer lies i
In the Linux kernel, the following vulnerability has been resolved: ntfs3: fix circular locking dependency in run_unpac
In the Linux kernel, the following vulnerability has been resolved: pstore: ram_core: fix incorrect success return when
In the Linux kernel, the following vulnerability has been resolved: fbcon: check return value of con2fb_acquire_newinfo
In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix user_ref race between scrub and
In the Linux kernel, the following vulnerability has been resolved: fs/buffer: add alert in try_to_free_buffers() for f
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix NULL pointer issue buffer funcs If
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/ras: Move ras data alloc before bad page
In the Linux kernel, the following vulnerability has been resolved: misc: bcm_vk: Fix possible null-pointer dereference
In the Linux kernel, the following vulnerability has been resolved: misc: ti_fpc202: fix a potential memory leak in pro
In the Linux kernel, the following vulnerability has been resolved: memory: mtk-smi: fix device leaks on common probe
In the Linux kernel, the following vulnerability has been resolved: memory: mtk-smi: fix device leak on larb probe Mak
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Drop the MHI auto_queue feature for IPCR
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Use devm_kmemdup() in rtw_set_supporte
In the Linux kernel, the following vulnerability has been resolved: most: core: fix resource leak in most_register_inte
In the Linux kernel, the following vulnerability has been resolved: hfsplus: ensure sb->s_fs_info is always cleaned up
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Polic
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a
FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileNam
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: annotate data-races around hde
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after
In the Linux kernel, the following vulnerability has been resolved: srcu: Use irq_work to start GP in tiny SRCU Tiny S
In the Linux kernel, the following vulnerability has been resolved: x86: shadow stacks: proper error handling for mmap
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pd-mapper: Fix element length in servreg
In the Linux kernel, the following vulnerability has been resolved: xfrm: account XFRMA_IF_ID in aevent size calculatio
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started