In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing NULL checks for kstrdup() 1
In the Linux kernel, the following vulnerability has been resolved: xfs: scrub: unlock dquot before early return in quo
In the Linux kernel, the following vulnerability has been resolved: futex: Clear stale exiting pointer in futex_lock_pi
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Fix static_branch_dec() underflow f
In the Linux kernel, the following vulnerability has been resolved: pmdomain: bcm: bcm2835-power: Increase ASB control
In the Linux kernel, the following vulnerability has been resolved: i2c: cp2615: fix serial string NULL-deref at probe
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix missing runtime PM reference in ccs_mod
In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL deref in bond_debug_rlb_hash
In the Linux kernel, the following vulnerability has been resolved: NFC: nxp-nci: allow GPIOs to sleep Allow the firmw
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix NULL dereference on notify
In the Linux kernel, the following vulnerability has been resolved: crash_dump: don't log dm-crypt key bytes in read_ke
In the Linux kernel, the following vulnerability has been resolved: x86/platform/uv: Handle deconfigured sockets When
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Check set_default_submission() before
In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdirect_socket.send_io.b
In the Linux kernel, the following vulnerability has been resolved: smb: client: make use of smbdirect_socket.recv_io.c
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout
Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary
Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search quer
When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original
The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at le
The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and Task
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache A
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache Dolphi
The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, i
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1
The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3.
The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the I
The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0.
The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-
MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file owne
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NT
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor
Xibo is an open source digital signage platform with a web content management system and Windows display player software
Xibo is an open source digital signage platform with a web content management system and Windows display player software
Xibo is an open source digital signage platform with a web content management system and Windows display player software
A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all adm
In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/log
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version
A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allo
A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive informat
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definit
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started