WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows a
A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts
A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function
Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control S
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability a
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can
HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to acces
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability,
Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any addres
The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to ax
A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer derefere
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-head
A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed th
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected
The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users wi
The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables,
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route
The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, w
A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dial
A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the f
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the functio
Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa
A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can l
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" S
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started