Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.
Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows a
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restric
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompres
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, a low-
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an aut
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions st
Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titl
EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop
EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorizat
Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (
EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race (C++ UB) triggered by an A 1-phas
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This i
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to th
The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-ne
Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.
Buffer Overflow vulnerability in ZerBea hcxpcapngtool v. 7.0.1-43-g2ee308e allows a local attacker to obtain sensitive i
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to
A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurre
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona
A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown functio
A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown fun
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio
The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a s
River Past Audio Converter 7.7.16 contains a local buffer overflow vulnerability in the activation code field that allow
MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application
AnyBurn 4.3 contains a local buffer overflow vulnerability that allows local attackers to crash the application by suppl
Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cau
MegaPing contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplyin
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A re
A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown fun
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume se
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr
HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files
Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started