MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r
stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0.
Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environmen
dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF b
Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send
OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create adm
eToolz 3.4.8.0 contains a denial of service vulnerability that allows local attackers to crash the application by supply
Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin
Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credent
Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitra
Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator
ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credenti
Precurio Intranet Portal 2.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers t
2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executab
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This
Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Contr
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc
The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflect
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach
HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identifi
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected c
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code cont
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Disco
The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could al
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a
Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied ra
Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talis
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started