The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, a
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local informat
In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible escalation of privilege due to improper input validation. This could lead to local escal
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE ha
In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of se
In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin
Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote atta
Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity
Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary scrip
Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary scri
Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access parti
Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows loc
Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access o
Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bo
Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-b
Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers
Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-o
Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write ou
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulner
Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local att
Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafti
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3,
mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classna
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started