Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Inform
Insertion of Sensitive Information Into Sent Data vulnerability in ArgusTech BILGER allows Choosing Message Identifier.
Authorization Bypass Through User-Controlled Key vulnerability with user privileges in ArgusTech BILGER allows Exploitat
In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap api: Fix possible memory leak
In the Linux kernel, the following vulnerability has been resolved: wifi: iwl4965: Add missing check for create_singlet
In the Linux kernel, the following vulnerability has been resolved: media: hi846: Fix memleak in hi846_init_controls()
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix leak of 'r10bio->remaining' for reco
In the Linux kernel, the following vulnerability has been resolved: nfc: fix memory leak of se_io context in nfc_genl_s
In the Linux kernel, the following vulnerability has been resolved: sctp: check send stream number after wait_for_sndbu
In the Linux kernel, the following vulnerability has been resolved: udf: Do not update file length for failed writes to
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix null-ptr-deref on inode->i_op in ntfs
In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix NULL dereference on q->elevator in blk_
In the Linux kernel, the following vulnerability has been resolved: rcu/rcuscale: Stop kfree_scale_thread thread(s) aft
In the Linux kernel, the following vulnerability has been resolved: samples/bpf: Fix fout leak in hbm's run_bpf_prog F
In the Linux kernel, the following vulnerability has been resolved: media: bdisp: Add missing check for create_workqueu
In the Linux kernel, the following vulnerability has been resolved: drm/client: Fix memory leak in drm_client_modeset_p
In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Put the cdns set active part outside th
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: check for null return of devm_kzalloc(
In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8723bs: Fix locking in _rtw_jo
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove unused nvme_ls_waitq wait que
In the Linux kernel, the following vulnerability has been resolved: misc: vmw_balloon: fix memory leak with using debug
In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in ubifs_sysfs_init() When
In the Linux kernel, the following vulnerability has been resolved: wifi: iwl3945: Add missing check for create_singlet
In the Linux kernel, the following vulnerability has been resolved: ubifs: Free memory for tmpfile name When opening a
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: fix a possible null-pointer dereference
In the Linux kernel, the following vulnerability has been resolved: Drivers: vmbus: Check for channel allocation before
In the Linux kernel, the following vulnerability has been resolved: ubi: Fix unreferenced object reported by kmemleak i
In the Linux kernel, the following vulnerability has been resolved: ext4: fix i_disksize exceeding i_size problem in pa
In the Linux kernel, the following vulnerability has been resolved: block: ublk: make sure that block size is set corre
In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_mqs: move of_node_put() to the correct lo
In the Linux kernel, the following vulnerability has been resolved: driver: soc: xilinx: fix memory leak in xlnx_add_cb
In the Linux kernel, the following vulnerability has been resolved: arm64: acpi: Fix possible memory leak of ffh_ctxt
In the Linux kernel, the following vulnerability has been resolved: clk: imx: clk-imxrt1050: fix memory leak in imxrt10
The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,
The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly larg
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26. An app may be able t
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadO
A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iO
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26,
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS T
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 1
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Tahoe 26. An app
The issue was addressed by adding additional logic. This issue is fixed in Safari 26, macOS Tahoe 26. Visiting a malicio
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7, macOS Sono
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started