Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cro
Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Objec
In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to loca
Subscriber Broken Access Control in Genemy <= 1.6.6 versions.
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t
In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic er
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro
Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security
Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded
Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery
Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This iss
Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control S
Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Con
: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Acce
Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Leve
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs fro
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Secu
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no P
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool
Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi
Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authentica
In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. T
In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote i
In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to rem
In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This cou
In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to
In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv
In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead
In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory
OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to
OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined
OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match
OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparison
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started