A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma
ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoi
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 un
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memo
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An att
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/
Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denia
Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without outp
The FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plug
NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A su
NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-
NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative
NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator co
NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-c
There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This
There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered
The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by p
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLR
The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization.
X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto
rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-l
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, al
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization an
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication ru
rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the a
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows auth
Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strin
Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#in
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under speci
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. No
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval d
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts
A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown functi
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started