Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure befo
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permis
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body o
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has a
The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauth
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseFo
A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file c
A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the function UERadioCapabil
A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/ha
A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfigu
A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the f
A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file
A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/
A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp
A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the fun
A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admi
A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/pre
A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/openc
A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot
A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInf
Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized
jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user acco
Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's informa
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to i
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform sta
Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticat
TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform u
A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-c
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file
A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/fun
A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in t
A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in t
A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf
A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file sr
A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccm
A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the fil
A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderControlle
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publ
A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getPar
A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file Pa
A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub
A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/s
A flaw has been found in Open5GS up to 2.7.6. This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/s
A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c
A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discover
A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file
### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on
Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to i
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started