The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in
Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi
A configuration file on the local file system had improper input validation which could allow code execution and potenti
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potenti
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of
** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web ma
SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when
SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions tem
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that all
Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users
Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthoriz
Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), a
Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticat
SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based
Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could b
A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Mes
A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing
A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the funct
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when t
Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark
Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a rem
barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_
A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function
HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. Th
Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET
Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both col
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.jso
WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two u
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmail.json.php exposes t
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/Meet/iframe.php echoes the at
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSavePhoto.php is a legac
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySubscribers.json.php t
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php comp
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-
barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing val
barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_m
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1
A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and
A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 1
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS T
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started