Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacke
The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions
Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session ex
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions belo
Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose informati
In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local
In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new
In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility s
In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could
In multiple locations, there is a possible way to access data displayed on the screen due to side channel information di
In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could
In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input val
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a l
In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused
In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path trav
In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exh
In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical pa
In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused
In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead
In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the cod
In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActi
In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This c
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio str
In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This c
In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due to a logic error in
In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic er
In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo
In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead
In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission chec
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent
In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead t
In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credenti
In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. Th
In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local e
In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant fo
In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error i
In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. Thi
In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a mi
In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to
In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local
In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the inc
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could le
In onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing pe
In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could
In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to
In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to
PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.
In the Linux kernel, the following vulnerability has been resolved: netlink: avoid infinite retry looping in netlink_un
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started