WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay mo
Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonl
CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools incl
CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without aut
Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/ove
Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Ver
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc7609508355
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and a
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not ass
PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote,
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote,
There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allo
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote,
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote,
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote,
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote,
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authent
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remot
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that m
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under diff
Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-co
FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyO
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constru
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls im
Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/typ
Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sens
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the logi
A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceControl
Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsy
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporte
VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged t
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in req
Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricte
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 h
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompt
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before renderin
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which RE
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification m
The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned get
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(repo
The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived e
A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php o
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a danger
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started