A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confide
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated,
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of se
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem
A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS93
A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated,
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypa
Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmwar
A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows a
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a spec
Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affec
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exp
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which,
In the Linux kernel, the following vulnerability has been resolved: af_unix: Give up GC if MSG_PEEK intervened. Igor U
In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice
In the Linux kernel, the following vulnerability has been resolved: gve: fix incorrect buffer cleanup in gve_tx_clean_p
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: clone set on flush only Syzb
In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Fix kernel stack leak in ionic_create_c
In the Linux kernel, the following vulnerability has been resolved: HID: Add HID_CLAIMED_INPUT guards in raw_event call
In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix nd_tbl NULL dereference when IPv6
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close
In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: fix divide by zero in the offload p
In the Linux kernel, the following vulnerability has been resolved: ice: change XDP RxQ frag_size from DMA write length
In the Linux kernel, the following vulnerability has been resolved: nvmet-fcloop: Check remoteport port_state before ca
In the Linux kernel, the following vulnerability has been resolved: mm: thp: deny THP for files on anonymous inodes fi
In the Linux kernel, the following vulnerability has been resolved: blktrace: fix __this_cpu_read/write in preemptible
In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: Don't default to -EOPNOTSUPP in rsi_mac8
In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix missing ENQUEUE_REPLENISH durin
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump plain
In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Revert "i2c: i801: replace acpi_lock wit
In the Linux kernel, the following vulnerability has been resolved: net: phy: register phy led_triggers during probe to
In the Linux kernel, the following vulnerability has been resolved: wifi: radiotap: reject radiotap with unknown bits
In the Linux kernel, the following vulnerability has been resolved: drm/client: Do not destroy NULL modes 'modes' in d
In the Linux kernel, the following vulnerability has been resolved: net: usb: kalmia: validate USB endpoints The kalmi
In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix locking for bcm_op runtime updates C
In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin queue leak on controller reset Whe
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix error handling in slot reset If th
In the Linux kernel, the following vulnerability has been resolved: can: mcp251x: fix deadlock in error path of mcp251x
In the Linux kernel, the following vulnerability has been resolved: drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock(
In the Linux kernel, the following vulnerability has been resolved: ata: libata: cancel pending work after clearing def
In the Linux kernel, the following vulnerability has been resolved: ice: fix crash in ethtool offline loopback test Si
In the Linux kernel, the following vulnerability has been resolved: x86/efi: defer freeing of boot services memory efi
In the Linux kernel, the following vulnerability has been resolved: HID: pidff: Fix condition effect bit clearing As r
In the Linux kernel, the following vulnerability has been resolved: cxl: Fix race of nvdimm_bus object when creating nv
In the Linux kernel, the following vulnerability has been resolved: can: usb: f81604: correctly anchor the urb in the r
In the Linux kernel, the following vulnerability has been resolved: arm64: io: Extract user memory type in ioremap_prot
In the Linux kernel, the following vulnerability has been resolved: arm64: gcs: Do not set PTE_SHARED on GCS mappings i
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix race in cpumap on PREEMPT_RT On PREEMPT_R
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started