OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows l
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mu
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limit
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or c
OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-t
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature t
OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-rea
OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enab
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and abov
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p
The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and abov
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and abov
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientH
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dc
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Cu
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on
A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to
An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB
An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut
SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation at
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv
remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed t
CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w
An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-ma
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.
The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin
AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on t
During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started