A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language M
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?ac
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /as
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a mani
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the co
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the
A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of t
A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_
A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/na
A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_m
A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/mig
A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_c
A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affe
A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown
A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_han
A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component N
Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authent
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-vi
SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*pa
SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/mo
WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administ
WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint
WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php tha
A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the compo
A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the fi
browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or
browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing atta
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of th
Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-
Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the fi
A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can
A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the compone
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unkn
A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages
A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tc
### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a t
A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknow
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of t
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processin
Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata f
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT acces
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content
Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested
pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.val
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 21,780 CVE records rated MEDIUM in our database. Of these, 15 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started