changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include
LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolve
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Respo
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticate
Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authentic
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:re
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown
A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manip
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle UR
Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow w
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21,
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing ta
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 20
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 20
LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model
LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoi
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_ap
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file
A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /ad
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint,
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in in the v
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex
A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_me
A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evalu
Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticat
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function i
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` e
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner
Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i
A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Categ
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without
The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, a
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote at
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started