Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not p
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdo
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditi
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin d
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based p
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bul
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-o
Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass c
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() stri
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize()
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restricti
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk
opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing tel
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synaps
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansio
When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to at
In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Ac
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr
PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u
PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to url
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr
A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that
In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Fix runtime PM refcount leak in
In the Linux kernel, the following vulnerability has been resolved: media: rc: xbox_remote: heed DMA restrictions The
In the Linux kernel, the following vulnerability has been resolved: media: saa7164: add ioremap return checks and clean
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: only purge non-released claims Wh
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: put backbone reference on failed c
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Clear VRAM on allocation to prevent sta
In the Linux kernel, the following vulnerability has been resolved: spi: ch341: fix devres lifetime USB drivers bind t
In the Linux kernel, the following vulnerability has been resolved: spi: fsl: fix controller deregistration Make sure
In the Linux kernel, the following vulnerability has been resolved: spi: rspi: fix controller deregistration Make sure
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix bo leak in xe_dma_buf_init_obj() on all
In the Linux kernel, the following vulnerability has been resolved: cgroup: Defer css percpu_ref kill on rmdir until cg
In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: Add missing MUST_CONNECT fl
In the Linux kernel, the following vulnerability has been resolved: EDAC/versalnet: Fix device name memory leak The de
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fe
In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Add NULL check for media_gt in intel_h
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix accept queue count leak on transp
In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: fix error handling in msm_ioctl_gem_in
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix empty payload in tap skb for non-
In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: run inactivity autodim from workq
In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix controller deregistration Make s
In the Linux kernel, the following vulnerability has been resolved: tracepoint: balance regfunc() on func_add() failure
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started