A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifical
CWE-284: Improper Access Control
CWE-620: Unverified Password Change
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set
Information disclosure while processing a packet at EAVB BE side with invalid header length.
Information disclosure while capturing logs as eSE debug messages are logged.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Information disclosure while opening a fastrpc session when domain is not sanitized.
The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun
Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric GENESIS64 versions 10.97.3
Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers
Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged a
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung He
Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bou
Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged att
Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allo
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document s
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers
Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to a
Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to mod
Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to a
Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to dea
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access
The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown W
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all ver
Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect
Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulne
Vulnerability of using incompatible types to access resources in the location service. Impact: Successful exploitation o
Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of t
Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of t
Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability
Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successfu
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Succe
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Succe
Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exp
Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful
ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cau
ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cau
The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the w
Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability m
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Succe
Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successfu
Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of
Out-of-bounds read vulnerability in the register configuration of the DMA module. Impact: Successful exploitation of thi
Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulner
Vulnerability of insufficient data length verification in the partition module. Impact: Successful exploitation of this
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started