Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated a
Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorize
A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the rout
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, Fo
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device leak on aperture remov
In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-b
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial st
In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_
WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not p
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),
The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored
The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10.
Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in th
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c
In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying i
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issu
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu
Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following')
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Ap
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: throu
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser
Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may
Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availab
Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect av
DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.
Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affec
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability
Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availabili
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started