The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences.
The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across file
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils during cross-device
A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the
The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during fil
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device
The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are init
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -
The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during f
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device m
The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries.
The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. Wh
A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementat
The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs co
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison
A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when usin
A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit co
The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple
DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and
A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before versi
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affect
Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to
Textpad 8.1.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplyi
ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML
UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image
Angry IP Scanner 3.5.3 contains a buffer overflow vulnerability in the preferences dialog that allows local attackers to
Angry IP Scanner for Linux 3.5.3 contains a denial of service vulnerability that allows local attackers to crash the app
A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially craf
A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across differen
An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data,
A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondar
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domai
A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, trig
A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddres
A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 conn
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH bac
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSd
In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix leakage in __construct_region() Fa
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix exception exit lock checking for subprogs
In the Linux kernel, the following vulnerability has been resolved: HID: asus: avoid memory leak in asus_report_fixup()
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A us
In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: avoid memory leak in magicmouse_re
In the Linux kernel, the following vulnerability has been resolved: module: Fix kernel panic when a symbol st_shndx is
In the Linux kernel, the following vulnerability has been resolved: HID: apple: avoid memory leak in apple_report_fixup
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started