pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-p
pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token vali
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal netw
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrep
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied dur
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or s
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values be
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to th
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds th
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation che
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when impor
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, al
The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and th
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling be
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints
The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its setti
The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() i
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the G
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.se
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limi
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat
Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c vali
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not
StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfi
Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attac
StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override exec
Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback en
Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset e
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authen
Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission check
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing una
Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry pat
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint th
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 43,624 CVE records rated MEDIUM in our database. Of these, 15 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started