MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Comput
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 1
Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actual
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users
Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/sla
Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, al
Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function atte
Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished j
Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exis
Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scri
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a com
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if th
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,
CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to sus
A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and belo
SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that on
Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to sym
Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capa
Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modificati
Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functio
The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterpr
Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe
Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code blo
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0
Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor
Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor
fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, i
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a mi
EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated
EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has b
EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat
EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol.
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An atta
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the
EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by
EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermet
GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin at
GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attac
Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories th
GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can cra
OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers ca
Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE
A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, l
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started