:Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulne
Race condition issue occurring in the physical page import process of the memory management module. Impact: Successful e
Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of thi
Pointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect
Race condition vulnerability in the kernel file system module. Impact: Successful exploitation of this vulnerability may
Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerab
Kenwood DMX958XR Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows physically pre
Kenwood DMX958XR libSystemLib Command injection Remote Code Execution Vulnerability. This vulnerability allows physicall
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical
Kenwood DMX958XR libSystemLib Command Injection Remote Code Execution Vulnerability. This vulnerability allows physicall
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several sh
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via th
The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ paramet
The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view short
The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ paramete
Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may
Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory r
Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerabi
Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause i
Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerabil
Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability c
Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability m
Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of thi
Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may af
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may
Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started