Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authori
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a
Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload ha
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site script
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` function in `kernel/ut
Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c
Halloy is an IRC application written in Rust. Prior to commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6, the DCC receive
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the
A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileg
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticate
libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream ca
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability
A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh
A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the fil
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the
PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3,
SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-U
A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vul
Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault confi
XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.
File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" func
File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" function
File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of th
DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field proj
A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator ac
A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an admi
An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, th
An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a l
A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c
An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora.
Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject
Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, t
Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unau
Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability e
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists i
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability e
Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a F
Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Clas
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-s
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callb
ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users t
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea
Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started