Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint all
Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_se
A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local
In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability
Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role Sys
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior,
Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can creat
wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc emb
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulner
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulner
A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserControlle
A vulnerability was detected in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the fil
A vulnerability was determined in Open5GS up to 2.7.7. This impacts the function ogs_sbi_discovery_option_add_snssais in
A vulnerability was found in Open5GS up to 2.7.7. This affects the function ogs_sbi_discovery_option_add_service_names i
A vulnerability has been found in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_parse_plmn_list in t
A flaw has been found in Open5GS up to 2.7.7. The affected element is the function nssf_nnrf_nsselection_handle_get_from
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unkno
A weakness has been identified in huangjunsen0406 xiaozhi-mcphub up to 1.0.3. This vulnerability affects unknown code of
A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the fil
A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the fil
A vulnerability was determined in 8421bit MiniClaw up to 43905b934cf76489ab28e4d17da28ee97970f91f. Affected by this vuln
A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function e
A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page th
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attack
Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor previ
Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. Th
A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the fi
i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes.
Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internat
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use
A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frm
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assi
ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0.
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds,
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit
ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa
A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file f
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user hold
A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality
A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supp
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started