Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow acc
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per
Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's a
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.
DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availabilit
Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availab
Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe
Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect ava
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directo
Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detec
The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where
Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members
PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals
n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configu
n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option,
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Pri
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capab
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is s
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Ser
A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown
A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplat
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::g
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra a
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, ca
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, m
A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of t
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE san
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started