Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the stand
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open Web
GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 micr
Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length
SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality.
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A s
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repos
@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for sto
A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli
A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browse
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file ag
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel
Memory Corruption when processing registry values with incorrect types using a direct query method.
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_
marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat
Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop
Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in
A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect
A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an
Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153
Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human
URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUM
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and
The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be
The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log en
The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef
The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect
The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po
The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler
The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started