This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, mac
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, ma
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonom
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 2
A flaw has been found in SourceCodester Sales and Inventory System 1.0. The affected element is an unknown function of t
A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an unknown function of the fi
A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0. This issue affects some unk
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of th
An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service inform
Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to byp
NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registr
NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an i
NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authoriza
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in th
solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organiza
Keystone is a content management system for Node.js. Prior to version 6.5.2, {field}.isFilterable access control can be
pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoof
HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provid
Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path
Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path head
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full reque
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in c
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scrip
Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control pa
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:pr
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started