In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix segfault with PEBS-via-PT with
In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Limit signal/freq counts in summary outpu
In the Linux kernel, the following vulnerability has been resolved: idpf: fix null-ptr-deref in idpf_features_check id
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix kernel NULL pointer dereference whe
In the Linux kernel, the following vulnerability has been resolved: virtio_ring: Fix data race by tagging event_trigger
In the Linux kernel, the following vulnerability has been resolved: x86/fred: Fix system hang during S4 resume with FRE
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix debug actions order The order o
In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: set device_caps for 417 The video_
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Set dma_mask for ffa devices Se
In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma-glue: Drop skip_fdq argument
In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: h616: Reparent GPU clock during freq
In the Linux kernel, the following vulnerability has been resolved: serial: mctrl_gpio: split disable_ms into sync and
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid WARN_ON when configuring MQPRIO wi
In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: Remove unnecessary driver_lock
In the Linux kernel, the following vulnerability has been resolved: vxlan: Annotate FDB data races The 'used' and 'upd
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Perform early GT MMIO initialization to
In the Linux kernel, the following vulnerability has been resolved: btrfs: correct the order of prelim_ref arguments in
In the Linux kernel, the following vulnerability has been resolved: x86/Kconfig: make CFI_AUTO_DEFAULT depend on !RUST
In the Linux kernel, the following vulnerability has been resolved: mr: consolidate the ipmr_can_free_table() checks.
In the Linux kernel, the following vulnerability has been resolved: padata: do not leak refcount in reorder_work A rec
In the Linux kernel, the following vulnerability has been resolved: kasan: avoid sleepable page allocation from atomic
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7606: check for NULL before calling sw_
In the Linux kernel, the following vulnerability has been resolved: nfs: handle failure of nfs_get_lock_context in unlo
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null check of pipe_ctx->plane_
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Disable MACsec offload for uplink repres
In the Linux kernel, the following vulnerability has been resolved: fs/eventpoll: fix endless busy loop after timeout h
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix memory leak in error handling
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Refactor remove call with idxd_cle
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: csa unmap use uninterruptible lock Aft
In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Use a bitmask for UTMI pad power
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: disable napi on driver removal A warni
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted mem
In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Add NULL check in uclogic_input_confi
In the Linux kernel, the following vulnerability has been resolved: net: mctp: Don't access ifa_index when missing In
Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIB
The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing the
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A succ
Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege E
A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial
A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7
A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allo
A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allo
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_data
An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could h
An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to esc
An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an att
A cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows a
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started