An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.6, watchOS 26
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8,
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.10 and iPadOS
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequ
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is f
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Ta
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.
Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized
Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memor
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr
The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a s
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per
Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Ap
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality
phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an i
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized c
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows att
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versi
Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started