vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions Complet
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x *
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex paramet
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune
rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remot
rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is use
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows
rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows atta
rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply a
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that al
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon recei
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-al
rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a ma
rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope o
rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allow
rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-leve
@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version
Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo
ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstan
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions.
Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started