LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permi
InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PA
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and a
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_ass
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /ap
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for tick
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoin
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zamma
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was miss
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for tic
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (m
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad
Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)
Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user w
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u
An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically all
Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-12
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products all
Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an
Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy be
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction()
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling
@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in ser
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the previ
In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer
The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Cu
A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f
A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from
A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi
A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact
CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and se
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started