IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi
Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace bo
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there
A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versi
An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitati
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOA
quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB wr
Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.
The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand return
Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Ar
Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colon
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and
LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. I
A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. Thi
A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file int
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter ext
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter ext
A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only pr
The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configu
An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and
GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations t
A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influenc
A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used th
A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is
An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_lo
A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a loc
An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template i
A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxi
A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the
A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the
A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file
A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file applicati
A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PH
WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attacker
WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attack
WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticat
Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete
GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malic
Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to
Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that al
Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject m
A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the libra
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMembe
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started