In the Linux kernel, the following vulnerability has been resolved: block: reject bs > ps block devices when THP is dis
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: account for Ethernet header i
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid
CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.
In the Linux kernel, the following vulnerability has been resolved: drm/scheduler: signal scheduled fence when kill job
In the Linux kernel, the following vulnerability has been resolved: riscv: fix runtime constant support for nommu kerne
In the Linux kernel, the following vulnerability has been resolved: net: netpoll: Initialize UDP checksum field before
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix regression with native SMB symlink
In the Linux kernel, the following vulnerability has been resolved: video: screen_info: Relocate framebuffers behind PC
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add basic validation for RAS header If
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: do not ping device which has failed
CNCF Harbor 2.13.x before 2.13.1 and 2.12.x before 2.12.4 allows information disclosure by administrators who can exploi
The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions
A vulnerability was found in PHPGurukul Login and User Management System 3.3. It has been declared as critical. This vul
Apwide Golive 10.2.0 Jira plugin allows Server-Side Request Forgery (SSRF) via the test webhook function.
In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Cleanup acquired resources when r
In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Release rproc->clean_table after
In the Linux kernel, the following vulnerability has been resolved: ice: fix eswitch code memory leak in reset scenario
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition f
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix a fence leak in submit error path In
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix another leak in the submit error path
In the Linux kernel, the following vulnerability has been resolved: riscv: cpu_ops_sbi: Use static array for boot_data
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: remove WARN on bad firmware input If
In the Linux kernel, the following vulnerability has been resolved: usb: typec: displayport: Fix potential deadlock Th
A vulnerability was found in PHPGurukul User Registration & Login and User Management 3.3. It has been classified as cri
A vulnerability was found in PHPGurukul User Registration & Login and User Management 3.3 and classified as critical. Af
A reflected cross-site scripting (XSS) vulnerability exists in Institute-of-Current-Students v1.0 via the email paramete
In the Linux kernel, the following vulnerability has been resolved: idpf: return 0 size for RSS key if not supported R
In the Linux kernel, the following vulnerability has been resolved: nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_ne
In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix suspicious RCU usage warning W
In the Linux kernel, the following vulnerability has been resolved: idpf: convert control queue mutex to a spinlock Wi
In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: do not index inva
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix memory leak by freeing notif
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Replace mutex with rwlock to avo
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Initialize obj_event->obj_sub_list befor
In the Linux kernel, the following vulnerability has been resolved: mtd: spinand: fix memory leak of ECC engine conf M
In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix data race in show_numa_info() The
In the Linux kernel, the following vulnerability has been resolved: Input: cs40l50-vibra - fix potential NULL dereferen
In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: udc: disconnect/reconnect from host
In the Linux kernel, the following vulnerability has been resolved: optee: ffa: fix sleep in atomic context The OP-TEE
In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix potential deadlock in MR deregistratio
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Disable interrupts before resetting the GP
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix failure to rebuild free space tree using
In the Linux kernel, the following vulnerability has been resolved: misc: tps6594-pfsm: Add NULL pointer check in tps65
In the Linux kernel, the following vulnerability has been resolved: maple_tree: fix MA_STATE_PREALLOC flag in mas_preal
In the Linux kernel, the following vulnerability has been resolved: drm/tegra: Fix a possible null pointer dereference
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null pointer check for get_fir
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add more checks for DSC / HUBP ONO
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix in_atomic() handling in do_secure_stor
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race between async reclaim worker and cl
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started