IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutraliza
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to imp
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to add unexpected parameters to a command due t
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearc
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.
XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme
XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1.
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated us
An authenticated user without repository read permission may access package metadata under specific conditions.
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit
A low-privileged authenticated user may access restricted support information under specific conditions.
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessi
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible l
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arb
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions req
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriv
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co
Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.
An unauthenticated user may bypass authentication under specific cache conditions.
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
A bundle writer may create misleading release promotion information under specific conditions.
A repository publisher without delete permission may modify protected package content under specific conditions.
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi
An authenticated user may view private Puppet module metadata without repository read access.
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
An unauthenticated user may access restricted repository information under specific conditions.
Credentials for a deleted user may remain valid for a short period under specific conditions.
regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started