An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow a
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and ear
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the admi
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the admi
Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Edit
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Face
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dy
Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more t
An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929
A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile
html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js cont
BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP
AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through
Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notifi
Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter.
Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.
A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically prox
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive i
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls comman
The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker co
In the Linux kernel, the following vulnerability has been resolved: mptcp: ensure context reset on disconnect() After
In the Linux kernel, the following vulnerability has been resolved: cpuset: fix warning when disabling remote partition
In the Linux kernel, the following vulnerability has been resolved: drm/tilcdc: Fix removal actions in case of failed p
In the Linux kernel, the following vulnerability has been resolved: kernel/kexec: fix IMA when allocation happens in CM
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add missing NULL pointer check for pin
In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix possible null-pointer dereferences in
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: change all pageblocks migrate type o
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments T
In the Linux kernel, the following vulnerability has been resolved: tracing: Do not register unsupported perf events S
In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: move preempt_prepare_postamble after
In the Linux kernel, the following vulnerability has been resolved: parisc: Do not reprogram affinitiy on ASP chip The
In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec: Enable SMT before waking offline CPU
In the Linux kernel, the following vulnerability has been resolved: ACPICA: Avoid walking the Namespace if start_node i
In the Linux kernel, the following vulnerability has been resolved: block: Remove queue freezing from several sysfs sto
In the Linux kernel, the following vulnerability has been resolved: um: init cpu_tasks[] earlier This is currently don
In the Linux kernel, the following vulnerability has been resolved: via_wdt: fix critical boot hang due to unnamed reso
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - zero initialize memory allocated v
In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) Convert macros to functions to avo
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Handle incorrect num_connectors c
In the Linux kernel, the following vulnerability has been resolved: f2fs: ensure node page reads complete before f2fs_p
In the Linux kernel, the following vulnerability has been resolved: fs: PM: Fix reverse check in filesystems_freeze_cal
In the Linux kernel, the following vulnerability has been resolved: f2fs: use global inline_xattr_slab instead of per-s
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix VM hard lockup after prolonged inacti
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started