Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the r
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an e
A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminal
A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function
Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description
Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management
A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write pat
A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver
The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding i
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to
A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserv
The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When de
A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report T
When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing th
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values w
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choos
ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without strippin
Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks m
Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then rende
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals())
libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js u
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauth
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to applicat
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory ex
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau
openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing
openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_pat
openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution fla
openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specifi
openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set m
In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to
openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, al
The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each admi
darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's
The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute i
tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src
tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/htt
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started