A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainf
A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of th
A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library
A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-p
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
libexpat before 2.8.2 has an integer overflow in copyString.
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse
libexpat before 2.8.2 has an integer overflow in getAttributeId.
libexpat before 2.8.2 has an integer overflow in addBinding.
libexpat before 2.8.2 has an integer overflow in storeAtts.
Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the ex
Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site
Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/pre
Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user with
Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the
Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where
Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint t
Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows
Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users
Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations th
Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_vi
A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_open
A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the
A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_ope
A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::exec
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerabi
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unk
A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects a
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the functi
A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the
A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/pro
A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file
AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering d
AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that
AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows aut
vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Severa
Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to re
Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that
Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript compo
Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudf
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr
Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-exp
capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSuc
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that
Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metri
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started