Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malf
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file tracer
A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-o
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap b
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive inform
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-bas
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecu
TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Ora
phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / b
NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to esca
Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request t
Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registra
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.
CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitra
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TR
The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on pu
Private Repository Existence Disclosure via go-get Meta Endpoint
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private rep
Repository migration SSRF via multi-answer DNS allow-list bypass
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of pr
Gitea LFS Deploy-Key Privilege Escalation
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti
Public-only API token restriction is not enforced on team API routes
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Local File Inclusion via file:// URI in Migration Restore
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Cross-repository issue/comment attachment re-linking can expose private attachment content
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
Gitea SSH Key Parser Denial of Service
Email Management API Bypasses ManageCredentials Feature Restrictions
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creat
Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in clas
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice i
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started