A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com
A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the componen
A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/com
A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissio
A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc
A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/appli
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the d
The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives
TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u
CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constru
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's
Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, whic
A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions
A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only
OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus
An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor
An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authe
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost
An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started