Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada
AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redire
In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of m
In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input vali
In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input v
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing lim
In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lea
In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This coul
In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input v
In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input v
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html withou
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not rev
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not valid
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored i
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor r
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint return
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, a stored XSS vulnerability exists i
An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13
Transient DOS when MAC configures config id greater than supported maximum value.
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limi
In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an
Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute
Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sani
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne
Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi
Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted
A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earli
Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi
Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?te
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Ma
The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such
The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security
In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malic
In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible system crash due to use after free. This could lead to local denial of service if a mali
In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In imgsys, there is a possible system crash due to use after free. This could lead to local denial of service if a malic
In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privileg
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started