In the Linux kernel, the following vulnerability has been resolved: mm: page_ext: add count limit to page_ext_iter_next
In the Linux kernel, the following vulnerability has been resolved: mm: do file ownership checks with the proper mount
In the Linux kernel, the following vulnerability has been resolved: iommufd: Move vevent memory allocation outside spin
In the Linux kernel, the following vulnerability has been resolved: iommufd: Set veventq_depth upper bound iommufd_vev
In the Linux kernel, the following vulnerability has been resolved: iommufd: Break the loop on failure in iommufd_fault
In the Linux kernel, the following vulnerability has been resolved: iommufd: Set upper bounds on cache invalidation ent
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Avoid dereferencing NULL VNCR pseud
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Pin source page for write when adding CPU
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Don't leak PFN when kvm_translate_vncr(
In the Linux kernel, the following vulnerability has been resolved: i2c: imx-lpi2c: mark I2C adapter when hardware is p
In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - prevent division by zero and arit
In the Linux kernel, the following vulnerability has been resolved: fuse: avoid 32-bit prune notification count wrap F
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix EFAULT clobber in fuse_uring_commit
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix moving cancelled entry to ent_in_us
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: end fuse_req on io-uring cancel task wo
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: remove request-less entries from ent_w_
In the Linux kernel, the following vulnerability has been resolved: xfs: don't wrap around quota ids in dqiterate LOLL
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all version
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes tha
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes
Weintek cMT3092X HMI stores user account passwords in plaintext.
An attacker can modify data that should be restricted to read‑only access.
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video de
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk
Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract ar
In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER
In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() P
In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Prevent initial console buffer from land
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Report dying CPU to RCU in stop_this_cpu
In the Linux kernel, the following vulnerability has been resolved: MIPS: smp: report dying CPU to RCU in stop_this_cpu
In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: set mem->altmap after successf
In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: teardown bugs and resource leaks A
In the Linux kernel, the following vulnerability has been resolved: media: rc: igorplugusb: fix control request setup p
In the Linux kernel, the following vulnerability has been resolved: gpio: shared: fix deadlock on shared proxy's parent
In the Linux kernel, the following vulnerability has been resolved: i2c: davinci: fix division by zero on missing clock
In the Linux kernel, the following vulnerability has been resolved: tty: serial: pch_uart: add check for dma_alloc_cohe
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: hold opts->lock across XU walks i
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: don't dump registers past the mapped r
In the Linux kernel, the following vulnerability has been resolved: regulator: tps65219: fix irq_data.rdev not being as
In the Linux kernel, the following vulnerability has been resolved: x86/mm: Disable broadcast TLB flush when PCID is di
In the Linux kernel, the following vulnerability has been resolved: net: ethtool: phy: avoid NULL deref when PHY driver
In the Linux kernel, the following vulnerability has been resolved: ACPI: driver: Check ACPI_COMPANION() against NULL d
In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in f
In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send
In the Linux kernel, the following vulnerability has been resolved: powerpc/time: Remove redundant preempt_disable|enab
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started