In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U
Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Se
A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the
A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileConten
A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the funct
SQL Injection affecting the Access Manager role.
A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The a
A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown pr
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate
A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the fil
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in
Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL
Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect ha
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Split
Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supp
Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their perm
Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to cras
NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by sup
Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to del
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove pass
A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unk
A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of
A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the
A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated att
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown
A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function dele
A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of th
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. I
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a we
A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of th
A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. T
A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This imp
A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API.
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil element
A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. Thi
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing
A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /g
A security flaw has been discovered in Edimax BR-6675nD 1.12. Impacted is the function mp of the file /goform/mp of the
A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request
A vulnerability has been found in code-projects Employee Management System 1.0. Affected by this issue is some unknown f
A flaw has been found in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown func
A vulnerability was detected in code-projects Employee Management System 1.0. Affected is an unknown function of the fil
A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown func
A weakness has been identified in code-projects Employee Management System 1.0. This affects an unknown function of the
A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown functio
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started