Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime all
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2
Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter funct
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability th
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid imag
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1
In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequen
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequen
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles
A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface inv
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same devi
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in con
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderb
Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.
Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri
A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an
A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid
A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p
A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation
An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerabi
Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Co
In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registratio
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsAction
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th
Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue a
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. Thi
Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: bef
Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname
Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issu
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects
There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started