In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Prevent potential NULL dereferenc
In the Linux kernel, the following vulnerability has been resolved: cxgb4: fix memory leak in cxgb4_init_ethtool_filter
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: avoid unregistering devlink re
In the Linux kernel, the following vulnerability has been resolved: net: ti: icss-iep: Fix possible NULL pointer derefe
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Fix error pointers in dpu_plane_virtua
In the Linux kernel, the following vulnerability has been resolved: i2c: cros-ec-tunnel: defer probe if parent EC is no
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix the warning from __kernel_write_iter [
In the Linux kernel, the following vulnerability has been resolved: virtiofs: add filesystem context source name check
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix workqueue crash in cma_netevent_work_
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Prevent division by zero The user can
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Prevent division by zero The user can
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm/smu11: Prevent division by zero The use
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Prevent division by zero The user can
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Prevent division by zero The user can
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Prevent division by zero The user can
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: fix firmware memory leaks Free th
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix missed dmabuf unpinning in error pa
In the Linux kernel, the following vulnerability has been resolved: mm/vma: add give_up_on_oom option on modify/merge,
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a craf
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it a
Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attacker
APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro
In the Linux kernel, the following vulnerability has been resolved: ublk: fix handling recovery & reissue in ublk_abort
In the Linux kernel, the following vulnerability has been resolved: ata: pata_pxa: Fix potential NULL pointer dereferen
In the Linux kernel, the following vulnerability has been resolved: drm/i915/huc: Fix fence not released on early probe
In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Fix NULL pointer deference in mtk_i
In the Linux kernel, the following vulnerability has been resolved: perf: Fix hang while freeing sigtrap event Perf ca
In the Linux kernel, the following vulnerability has been resolved: perf/dwc_pcie: fix duplicate pci_dev devices Durin
In the Linux kernel, the following vulnerability has been resolved: PM: hibernate: Avoid deadlock in hibernate_compress
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_pci_remove(
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid memory leak while enabling stat
In the Linux kernel, the following vulnerability has been resolved: jfs: Fix uninit-value access of imap allocated in t
In the Linux kernel, the following vulnerability has been resolved: jfs: add sanity check for agwidth in dbMount The w
In the Linux kernel, the following vulnerability has been resolved: net: vlan: don't propagate flags on open With the
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't try to trigger a full GT reset if
In the Linux kernel, the following vulnerability has been resolved: PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t t
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak relate
In the Linux kernel, the following vulnerability has been resolved: io_uring/net: fix io_req_post_cqe abuse by send bun
In the Linux kernel, the following vulnerability has been resolved: arm/crc-t10dif: fix use of out-of-scope array in cr
In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in
In the Linux kernel, the following vulnerability has been resolved: tpm: do not start chip while suspended Checking TP
In the Linux kernel, the following vulnerability has been resolved: soc: samsung: exynos-chipid: Add NULL pointer check
In the Linux kernel, the following vulnerability has been resolved: i3c: Add NULL pointer check in i3c_master_queue_ibi
In the Linux kernel, the following vulnerability has been resolved: mfd: ene-kb3930: Fix a potential NULL pointer deref
In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when callin
In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and
In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Avoid issue of interrupts
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead t
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started