In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a
In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due t
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC)
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper inp
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/ov
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapj
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an inte
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource ex
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer
In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to impro
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This cou
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote
ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions o
The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an
Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler t
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows re
A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown fu
A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php.
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the functi
A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the functio
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12,
Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer deref
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collab
Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before
Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper chec
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, a
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14,
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability
CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo
OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc
Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil
A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti
A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the fi
A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the
A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.
A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affect
A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of t
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute
Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started