An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches
The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could resul
Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event c
Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affe
Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut
A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitializ
In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration before IB connect
In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_che
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference o
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL pointer dereference on
In the Linux kernel, the following vulnerability has been resolved: bridge: mrp: reject zero test interval to avoid OOM
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in m
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink heade
In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6_datagram_send_ctl() Y
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig pa
Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows admin
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av
The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping"
Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affect
Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive in
Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attacker
Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged fu
Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitiv
Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to by
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP
A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown f
Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point
Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may ex
Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability m
Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect a
Race condition vulnerability in the power consumption statistics module. Impact: Successful exploitation of this vulnera
Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability a
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availabi
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availabi
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affec
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability a
Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg
Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg
Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attack
Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affe
Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect avail
Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect ava
Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulner
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started