In the Linux kernel, the following vulnerability has been resolved: dm thin: Use last transaction's pmd->root when comm
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mlme: fix null-ptr deref on failed
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix possible resource leaks in mpt3s
In the Linux kernel, the following vulnerability has been resolved: tipc: fix an information leak in tipc_topsrv_kern_s
In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix null pointer dereference in blk_mq_clea
In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_ini
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix size validation for non-exclusive d
In the Linux kernel, the following vulnerability has been resolved: iommu/fsl_pamu: Fix resource leak in fsl_pamu_probe
In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Check return value after calling pl
In the Linux kernel, the following vulnerability has been resolved: clk: rockchip: Fix memory leak in rockchip_clk_regi
In the Linux kernel, the following vulnerability has been resolved: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Fix PCI device refcount leak in radeon_
In the Linux kernel, the following vulnerability has been resolved: nilfs2: replace WARN_ONs by nilfs_error for checkpo
In the Linux kernel, the following vulnerability has been resolved: fs: dlm: fix invalid derefence of sb_lvbptr I expe
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix memory leak in hpd_rx_irq_create_wo
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: fix refcount leak on error path
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix a potential memory leak in
In the Linux kernel, the following vulnerability has been resolved: ext4: fix potential memory leak in ext4_fc_record_r
In the Linux kernel, the following vulnerability has been resolved: lib/fonts: fix undefined behavior in bit shift for
In the Linux kernel, the following vulnerability has been resolved: perf/smmuv3: Fix hotplug callback leak in arm_smmu_
In the Linux kernel, the following vulnerability has been resolved: media: coda: Add check for kmalloc As the kmalloc
A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unkno
A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5c
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A ma
A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter.
A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter
A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input p
A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unkn
A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the
A security vulnerability has been detected in code-projects Simple Banking System 1.0. The affected element is an unknow
The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featur
A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /
A security flaw has been discovered in code-projects Simple Banking System 1.0. This issue affects some unknown processi
A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file
A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of t
A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown
A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0
The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an
The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network a
The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-ac
Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet
A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Bas
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality o
A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4
Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started