A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca6
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix cache_request leak in cache_release Wh
In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for
In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - Fix OOM ->tfm_count leak I
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl Whe
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvide
Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibas
In the Linux kernel, the following vulnerability has been resolved: spi: fix statistics allocation The controller per-
In the Linux kernel, the following vulnerability has been resolved: mtd: Avoid boot crash in RedBoot partition table pa
In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix deadlock in soft reset sequenc
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Synchronize interrupts before susp
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent re
In the Linux kernel, the following vulnerability has been resolved: drm/i915/dmc: Fix an unlikely NULL pointer deferenc
In the Linux kernel, the following vulnerability has been resolved: btrfs: log new dentries when logging parent dir of
In the Linux kernel, the following vulnerability has been resolved: soc: microchip: mpfs: Fix memory leak in mpfs_sys_c
In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: fix race condition in qman_destroy
In the Linux kernel, the following vulnerability has been resolved: net/rose: fix NULL pointer dereference in rose_tran
In the Linux kernel, the following vulnerability has been resolved: PM: runtime: Fix a race condition related to device
In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Do not perform PM inside suspend
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata
In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Prevent concurrent access to IPSec ASO c
In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: fix NULL deref caused by udp_sock_creat
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: guard flow control update with global_t
In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect from late creation of hierarch
In the Linux kernel, the following vulnerability has been resolved: perf/x86: Move event pointer setup earlier in x86_p
In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Fix null pointer dereference when restori
In the Linux kernel, the following vulnerability has been resolved: spi: amlogic-spisg: Fix memory leak in aml_spisg_pr
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Don't overwrite KMS surface dirty track
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell m
A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL
An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the medi
An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read b
** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. Thi
In the Linux kernel, the following vulnerability has been resolved: drm/logicvc: Fix device node reference leak in logi
In the Linux kernel, the following vulnerability has been resolved: btrfs: free pages on error in btrfs_uring_read_exte
In the Linux kernel, the following vulnerability has been resolved: drm/xe/configfs: Free ctx_restore_mid_bb in release
In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Fix a locking bug Make sure that wl-
In the Linux kernel, the following vulnerability has been resolved: drm/xe/reg_sr: Fix leak on xa_store failure Free t
A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. I
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitiz
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plu
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started