A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/m
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs aga
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endp
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre
WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.ph
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that h
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5,
GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaL
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.
In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
A resample query can be used to trigger out-of-memory crashes in Grafana.
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u
BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proxi
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover
ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts
Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device infor
Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker w
Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This i
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sent
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and usern
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when un
WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the af
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for
Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1
A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.
MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a h
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket bac
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fing
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an un
The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started