A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include
apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKey
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before
A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf
A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of t
A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-
A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file
A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater o
A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the fi
The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to A
A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in th
A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c
A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of t
Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transm
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated u
Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amo
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to vie
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.acc
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks lice
The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthe
PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response
Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compou
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists
FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in M
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in
Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added i
FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists
SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoin
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with reta
nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-
Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand
Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (X
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsd
People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0,
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-suppli
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-priv
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configurat
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started