In the Linux kernel, the following vulnerability has been resolved: btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol
In the Linux kernel, the following vulnerability has been resolved: esp: fix skb leak with espintcp and async crypto W
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix skb_put() panic on non-linear skb
In the Linux kernel, the following vulnerability has been resolved: af_key: validate families in pfkey_send_migrate()
In the Linux kernel, the following vulnerability has been resolved: erofs: set fileio bio failed in short read case Fo
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate PDU length before readin
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix circular locking dependency in nci_cl
In the Linux kernel, the following vulnerability has been resolved: udp: Fix wildcard bind conflict check when using ha
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del()
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: clamp SCO altsetting table indice
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: skip expectations i
In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use netlink policy range chec
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Initialize free_qp completion before us
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Harden depth calculation functions An
In the Linux kernel, the following vulnerability has been resolved: spi: use generic driver_override infrastructure Wh
In the Linux kernel, the following vulnerability has been resolved: s390/syscalls: Add spectre boundary for syscall dis
In the Linux kernel, the following vulnerability has been resolved: s390/entry: Scrub r12 register on kernel entry Bef
In the Linux kernel, the following vulnerability has been resolved: tracing: Drain deferred trigger frees if kthread cr
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix potential deadlock in cpu hotplug with
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: validate inner IPv4 header length in I
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix folio isn't locked in softleaf_
In the Linux kernel, the following vulnerability has been resolved: writeback: don't block sync for filesystems with no
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: prevent immediate PASID reuse case PAS
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix drm_edid leak in amdgpu_dm [W
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check if ext_caps is valid in BL s
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix param_ctx leak on damon_sysfs_n
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: check contexts->nr before accessing
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: check contexts->nr in repeat_call_f
In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk: fix race between concurrent split and
In the Linux kernel, the following vulnerability has been resolved: ext4: replace BUG_ON with proper error handling in
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: avoid use of half-online-committed c
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix crash when the event log is di
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix memory leak when a wq is reset
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix leaking event log memory Duri
In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx: xdma: Fix regmap init error hand
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix kernel BUG in netfs_limit_iter() for ITE
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix NULL pointer dereference in netfs_unbuff
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix leak of kobject name for sub-group space
Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attacker
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistenc
An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leadin
A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni
Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressi
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started