In the Linux kernel, the following vulnerability has been resolved: LoongArch: mm: Add p?d_leaf() definitions When I d
In the Linux kernel, the following vulnerability has been resolved: USB: fix memory leak with using debugfs_lookup() W
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Add null pointer check in gs
In the Linux kernel, the following vulnerability has been resolved: staging: pi433: fix memory leak with using debugfs_
In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: postpone mem_mgr IDR destruction
In the Linux kernel, the following vulnerability has been resolved: drm/ttm: check null pointer before accessing when s
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Check scheduler work queue before callin
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix slicing memory leak The temporary
In the Linux kernel, the following vulnerability has been resolved: media: ov2740: Fix memleak in ov2740_init_controls(
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock when aborting transaction durin
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Handle pairing of E-switch via uplink un/
In the Linux kernel, the following vulnerability has been resolved: kernel/fail_function: fix memory leak with using de
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix potential data race in rxrpc_wait_to_be_
In the Linux kernel, the following vulnerability has been resolved: can: bcm: bcm_tx_setup(): fix KMSAN uninit-value in
In the Linux kernel, the following vulnerability has been resolved: icmp6: Fix null-ptr-deref of ip6_null_entry->rt6i_i
In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix handling IPv4 routes wi
In the Linux kernel, the following vulnerability has been resolved: of/fdt: run soc memory setup when early_init_dt_sca
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix BUG_ON condition in btrfs_cancel_balance
In the Linux kernel, the following vulnerability has been resolved: nilfs2: do not write dirty data after degenerating
In the Linux kernel, the following vulnerability has been resolved: media: ipu-bridge: Fix null pointer deref on SSDB/P
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_{ldisc,serdev}: check percpu_init_rw
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when build ntlmssp negotiate
In the Linux kernel, the following vulnerability has been resolved: led: qcom-lpg: Fix sleeping in atomic lpg_brighnes
In the Linux kernel, the following vulnerability has been resolved: i2c: designware: Fix handling of real but unexpecte
In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix null-ptr-deref in vkms_release() A n
In the Linux kernel, the following vulnerability has been resolved: i2c: mux: reg: check return value after calling pla
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: add missing unregister_netdev() in
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: fix aux-bus EP lifetime Device-managed
In the Linux kernel, the following vulnerability has been resolved: media: cx88: Fix a null-ptr-deref bug in buffer_pre
In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flo
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: fix some leaks in probe The dwc3_
In the Linux kernel, the following vulnerability has been resolved: net: sched: sfb: fix null pointer access issue when
In the Linux kernel, the following vulnerability has been resolved: mmc: wmt-sdmmc: fix return value check of mmc_add_h
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted fr
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profil
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intent
Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference wh
An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an
A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio
Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forcef
When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the pass
NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table a
A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknow
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside So
The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Ren
A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of th
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started