Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance co
Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information a
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability h
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter o
NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL hi
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be
A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 all
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFil
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric
An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Man
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endp
Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalat
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.1
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.
In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni
A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote
A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote
IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper
IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, w
IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticate
Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malic
IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details,
Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.
Kazaar 1.25.12 allows a JWT with none in the alg field.
Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPD
Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of T
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix deinitialization of firmware reso
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Use raw_smp_processor_id() instead o
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix memory leak in rtw88_usb Kmemleak
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix unsafe drain work queue code If crea
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix memory leak in tb_handle_dp_bandwi
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Allow UD qp_type to join multicast only
In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: fix time stamp counter initialization
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: add lock to protect parameter
In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix memory leak of device names The d
In the Linux kernel, the following vulnerability has been resolved: nbd: fix incomplete validation of ioctl arg We tes
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix a memory leak Add a forgotten k
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix fget leak when fs don't support nowai
In the Linux kernel, the following vulnerability has been resolved: qed: allow sleep in qed_mcp_trace_dump() By defaul
In the Linux kernel, the following vulnerability has been resolved: clk: tegra: tegra124-emc: Fix potential memory leak
In the Linux kernel, the following vulnerability has been resolved: ext4: allow ext4_get_group_info() to fail Previous
In the Linux kernel, the following vulnerability has been resolved: iommu/amd/iommu_v2: Fix pasid_state refcount dec hi
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential null dereference Th
In the Linux kernel, the following vulnerability has been resolved: media: vsp1: Replace vb2_is_streaming() with vb2_st
In the Linux kernel, the following vulnerability has been resolved: x86/platform/uv: Use alternate source for socket to
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started