OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens t
A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.
If the PATH environment variable contains paths which are executables (rather than just directories), passing certain st
A crafted system call argument can cause memory corruption.
IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version informat
IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the syste
IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged us
A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b
A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t
A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController o
In the Linux kernel, the following vulnerability has been resolved: f2fs: don't reset unchangable mount option in f2fs_
In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fix bulk_move corruption when adding a ent
In the Linux kernel, the following vulnerability has been resolved: mfd: arizona: Use pm_runtime_resume_and_get() to pr
In the Linux kernel, the following vulnerability has been resolved: ice: Block switchdev mode when ADQ is active and vi
In the Linux kernel, the following vulnerability has been resolved: bpf: cpumap: Fix memory leak in cpu_map_update_elem
In the Linux kernel, the following vulnerability has been resolved: net: skb_partial_csum_set() fix against transport h
In the Linux kernel, the following vulnerability has been resolved: x86/MCE: Always save CS register on AMD Zen IF Pois
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Handle cameras with invalid descri
In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible memory leak if device_add(
In the Linux kernel, the following vulnerability has been resolved: cassini: Fix a memory leak in the error handling pa
In the Linux kernel, the following vulnerability has been resolved: remoteproc: imx_dsp_rproc: Add custom memory copy i
In the Linux kernel, the following vulnerability has been resolved: net: add vlan_get_protocol_and_depth() helper Befo
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: dma: fix memory leak running mt76_dma_t
In the Linux kernel, the following vulnerability has been resolved: powercap: arm_scmi: Remove recursion while parsing
In the Linux kernel, the following vulnerability has been resolved: media: platform: mediatek: vpu: fix NULL ptr derefe
In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: fix of_iomap memory leak Smatch rep
In the Linux kernel, the following vulnerability has been resolved: objtool: Fix memory leak in create_static_call_sect
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fw: fix memory leak in debugfs Fix
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Reinit blkg_iostat_set after clearing i
In the Linux kernel, the following vulnerability has been resolved: rcu: Protect rcu_print_task_exp_stall() ->exp_tasks
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: mhi: fix potential memory leak in ath
In the Linux kernel, the following vulnerability has been resolved: irqchip/wpcm450: Fix memory leak in wpcm450_aic_of_
In the Linux kernel, the following vulnerability has been resolved: parisc: led: Fix potential null-ptr-deref in start_
In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Fix transport not deattached when fcoe_
In the Linux kernel, the following vulnerability has been resolved: net: If sock is dead don't access sock's sk_wq in s
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local
In the Linux kernel, the following vulnerability has been resolved: fbdev: fbcon: release buffer when fbcon_do_set_font
In the Linux kernel, the following vulnerability has been resolved: drivers/md/md-bitmap: check the return value of md_
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site sc
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representa
In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity a
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an
A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: lpc32xx_udc: fix memory leak with usin
In the Linux kernel, the following vulnerability has been resolved: USB: sl811: fix memory leak with using debugfs_look
In the Linux kernel, the following vulnerability has been resolved: USB: isp1362: fix memory leak with using debugfs_lo
In the Linux kernel, the following vulnerability has been resolved: USB: dwc3: fix memory leak with using debugfs_looku
In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix memory leak with using debugfs_look
In the Linux kernel, the following vulnerability has been resolved: USB: isp116x: fix memory leak with using debugfs_lo
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: bcm63xx_udc: fix memory leak with usin
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started