Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe
A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calc
Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t
Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files und
Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-f
vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a
Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL i
Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl
Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections
The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can se
pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource rea
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service v
Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The came
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The ca
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR compo
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch
A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affecte
A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /cus
A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown pro
A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown
A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file
A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unkn
A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData
A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/con
A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/mo
Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The
A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pk
A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view
A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this is
A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by th
A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unkn
A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the f
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /
The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenced an endp
Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This i
Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensit
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started