Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil
A vulnerability was found in BoyunCMS up to 1.4.20. It has been rated as critical. This issue affects some unknown proce
A vulnerability was found in BoyunCMS up to 1.4.20. It has been declared as critical. This vulnerability affects unknown
A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of
A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown fu
A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability
A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected i
A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of
A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this issue is the function f
A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this vulnerability is t
In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix "appletb_backlight" backlight
A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vu
A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/b
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connecti
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputSt
The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a
A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulner
Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes be
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal e
In the Linux kernel, the following vulnerability has been resolved: nfsd: Initialize ssc before laundromat_work to prev
In the Linux kernel, the following vulnerability has been resolved: media: cxusb: no longer judge rbuf when the write f
In the Linux kernel, the following vulnerability has been resolved: media: imagination: fix a potential memory leak in
In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Cleanup after an allocation error
In the Linux kernel, the following vulnerability has been resolved: ceph: avoid kernel BUG for encrypted inode with una
In the Linux kernel, the following vulnerability has been resolved: ext4: inline: fix len overflow in ext4_prepare_inli
In the Linux kernel, the following vulnerability has been resolved: ext4: only dirty folios when data journaling regula
In the Linux kernel, the following vulnerability has been resolved: f2fs: prevent kernel warning due to negative i_nlin
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ftsteutates) Fix TOCTOU race in fts_read()
In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix do_register_framebuffer to prevent null-
In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_set_var to prevent null-ptr-deref in
In the Linux kernel, the following vulnerability has been resolved: configfs-tsm-report: Fix NULL dereference of tsm_op
In the Linux kernel, the following vulnerability has been resolved: smb: client: add NULL check in automount_fullpath
In the Linux kernel, the following vulnerability has been resolved: mm: fix uprobe pte be overwritten when expanding vm
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid divide by zero by initializi
In the Linux kernel, the following vulnerability has been resolved: jfs: Fix null-ptr-deref in jfs_ioc_trim [ Syzkalle
In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() in bpf_map_lo
In the Linux kernel, the following vulnerability has been resolved: i40e: fix MMIO write access to an invalid page in i
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix memory leak due to multiple rx_st
In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: validate buffer count with offset fo
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte
In the Linux kernel, the following vulnerability has been resolved: jffs2: check that raw node were preallocated before
In the Linux kernel, the following vulnerability has been resolved: atm: Revert atm_account_tx() if copy_from_iter_full
In the Linux kernel, the following vulnerability has been resolved: drm/msm/a7xx: Call CP_RESET_CONTEXT_STATE Calling
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix double invocation of bnxt_ulp_stop()/b
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started