Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73
SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymC
dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admi
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/custo
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publ
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti
In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to impr
A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Im
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allo
Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugi
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post
Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML re
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tan
An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver
An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted
A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This is
The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url
An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit
Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Fo
vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Servi
vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.
vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side re
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privil
Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 a
An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attac
An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allow
An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo
An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitra
Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handle
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnera
A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts o
Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to
A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of th
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formC
UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the form
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtp
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the form
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started