In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix crash when destroying a suspende
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: free skb on nci_transceive early error pa
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: Do not allow userspace to trivial
In the Linux kernel, the following vulnerability has been resolved: pinctrl: pinconf-generic: Fix memory leak in pincon
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix kernel stack leak in irdma_create_u
In the Linux kernel, the following vulnerability has been resolved: can: usb: f81604: handle short interrupt urb messag
In the Linux kernel, the following vulnerability has been resolved: cpufreq: intel_pstate: Fix crash during turbo disab
In the Linux kernel, the following vulnerability has been resolved: udp: Unhash auto-bound connected sk from 4-tuple ha
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: complete pending data exchange on device
In the Linux kernel, the following vulnerability has been resolved: libie: don't unroll if fwlog isn't supported The l
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix NULL pointer dereference of mgmt
In the Linux kernel, the following vulnerability has been resolved: can: usb: etas_es58x: correctly anchor the urb in t
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: in-kernel: always mark signal+subflow en
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: fix ARM64 alignment fault in multipath h
In the Linux kernel, the following vulnerability has been resolved: regulator: bq257xx: Fix device node reference leak
In the Linux kernel, the following vulnerability has been resolved: i40e: Fix preempt count leak in napi poll tracepoin
In the Linux kernel, the following vulnerability has been resolved: net: usb: kaweth: validate USB endpoints The kawet
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix invalid wait context in ctx_sched_in
In the Linux kernel, the following vulnerability has been resolved: bpf/bonding: reject vlan+srcmac xmit_hash_policy ch
In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_fre
In the Linux kernel, the following vulnerability has been resolved: pinctrl: equilibrium: fix warning trace on load Th
In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): check t
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu(
In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cif
In the Linux kernel, the following vulnerability has been resolved: net: annotate data-races around sk->sk_{data_ready,
In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Add allocation failure check for Entity
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix panic when IPv4 route references loo
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: purge error queues in socket destructors
In the Linux kernel, the following vulnerability has been resolved: can: ucan: Fix infinite loop from zero-length messa
In the Linux kernel, the following vulnerability has been resolved: nfsd: Fix cred ref leak in nfsd_nl_threads_set_doit
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix refcount leak for tagset_refcnt Th
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix dead lock for suspend and resume
In the Linux kernel, the following vulnerability has been resolved: net: vxlan: fix nd_tbl NULL dereference when IPv6 i
In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix recursive locking in __configfs_o
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: properly drop the usb interface referen
In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: validate USB endpoints The pega
In the Linux kernel, the following vulnerability has been resolved: IB/mthca: Add missed mthca_unmap_user_db() for mthc
In the Linux kernel, the following vulnerability has been resolved: irqchip/sifive-plic: Fix frozen interrupt due to af
In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix null-ptr-deref in lec_arp_clear_vccs
In the Linux kernel, the following vulnerability has been resolved: drbd: fix null-pointer dereference on local read er
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Reset prog ptr to old_p
In the Linux kernel, the following vulnerability has been resolved: regulator: fp9931: Fix PM runtime reference leak in
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in s
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL pointer dereference in mes
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentic
SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the w
The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP arch
Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: fro
The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started