NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the fi
libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.1
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id,
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitr
Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a
Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2
Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciou
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou
Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcin
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit
SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript
SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenti
SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i
SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clause
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At
SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c
SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references.
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos
SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire
SurrealDB before 3.1.0 contains a capability bypass vulnerability in HTTP redirect handling that allows authenticated us
SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS
SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users
SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g
SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server
SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the
SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows aut
SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS
A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The int
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` a
The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encod
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started