Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows u
A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environmen
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 aut
A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file to
Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue a
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to mana
A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS)
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as
HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying
HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th
HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism
GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge
A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this is
A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file
A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The is
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the D
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Matter
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parseP
Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the tem
The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requ
The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticate
The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parame
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provide
Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Pr
Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a loc
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker
The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable t
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and
The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cros
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and
grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASec
Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that al
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started