Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used
IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allo
Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar
A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this
A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired
Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user inpu
PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency wit
In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" a
In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthoriz
A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the funct
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirec
iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM
A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of
Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on
parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateContr
json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setDa
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLi
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization
A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation
The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initializatio
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could pote
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow
A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user
The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Du
A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespa
Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerabi
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri
A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una
Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileg
A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for
A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attack
A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker
A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an un
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow
A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow a
Information disclosure when Video engine escape input data is less than expected minimum size.
Information disclosure while running video usecase having rogue firmware.
information disclosure while invoking calibration data from user space to update firmware size.
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GP
NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a mali
NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers
nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in p
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_rea
Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insu
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started