Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlockin
Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classifie
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stor
Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Securi
A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs1
A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This
A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The imp
A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected ele
A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticat
Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQ
A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown fun
A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box befo
A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows at
A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before
A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Pro
A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.0
A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A m
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a
A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the fil
A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown proce
A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the fil
Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.
The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by
Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the f
A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, *
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache Acti
Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi
A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked lo
The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly b
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections t
A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` /
A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names l
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A
Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization
A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable b
A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the fi
A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function
A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/
A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the f
A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started