In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL pointer dereference in tipc_mon_rein
In the Linux kernel, the following vulnerability has been resolved: sched/eevdf: Fix se->slice being set to U64_MAX and
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for i
In the Linux kernel, the following vulnerability has been resolved: mei: vsc: Fix fortify-panic caused by invalid count
In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: Fix Kernel panic during
In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Fix deadlock when using NCM gadget The
In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: ci_hdrc_imx: fix usbmisc handling u
In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Fix NULL pointer access Concurr
In the Linux kernel, the following vulnerability has been resolved: crypto: null - Use spin lock instead of mutex As t
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kmemleak warning for percpu hashmap Vlad
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Keep write operations atomic syzbot repo
In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitial
An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip
i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed an
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, s
On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with
Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI tem
When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may
An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system
gnuplot is affected by a heap buffer overflow at function utf8_copy_one.
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.
Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers c
Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the colle
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ direct
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is
A vulnerability in Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to re
A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote
A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an una
A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authen
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15
A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could a
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote at
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privile
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privile
A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authen
A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could
A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow a
A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, co
A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c
A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 100
Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configure
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-memb
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started