In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb_pmd_shared() Patch series
In the Linux kernel, the following vulnerability has been resolved: migrate: correct lock ordering for hugetlb file fol
In the Linux kernel, the following vulnerability has been resolved: uacce: fix cdev handling in the cleanup path When
In the Linux kernel, the following vulnerability has been resolved: uacce: fix isolate sysfs check condition uacce sup
In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbd: fix dma_unmap_sg() nents The dma_unma
In the Linux kernel, the following vulnerability has been resolved: intel_th: fix device leak on output open() Make su
In the Linux kernel, the following vulnerability has been resolved: slimbus: core: fix device reference leak on report
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash on synthetic stacktrace field us
In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Fix potential memory leak in s
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: cap TX credit to local buffer size T
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Avoid truncating memory address
In the Linux kernel, the following vulnerability has been resolved: be2net: Fix NULL pointer dereference in be_cmd_get_
In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): unanch
In the Linux kernel, the following vulnerability has been resolved: net: phy: intel-xway: fix OF node refcount leakage
In the Linux kernel, the following vulnerability has been resolved: can: mcba_usb: mcba_usb_read_bulk_callback(): fix U
In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: Fix resource leaks on errors in lineinf
In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: esd_usb_read_bulk_callback(): fix URB
In the Linux kernel, the following vulnerability has been resolved: l2tp: Fix memleak in l2tp_udp_encap_recv(). syzbot
In the Linux kernel, the following vulnerability has been resolved: regmap: Fix race condition in hwspinlock irqsave ro
In the Linux kernel, the following vulnerability has been resolved: Octeontx2-af: Add proper checks for fwdata firmwar
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential underflow in virtio_tra
In the Linux kernel, the following vulnerability has been resolved: iommu/io-pgtable-arm: fix size_t signedness bug in
In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: Fix memory leak in wbrf_record()
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: avoid possible NULL deref tcf_
In the Linux kernel, the following vulnerability has been resolved: uacce: ensure safe queue release with state managem
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: Fix kernel panic in GET_I
In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb: kvaser_usb_read_bulk_callback(): f
In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote
A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco S
A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secr
A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X r
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with con
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) s
A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password
An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers
Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling
The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedI
The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' para
The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' para
The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form
The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se
The Fortis for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an inverted nonce check in
The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a mis
The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t
The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in
The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization i
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started