IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id}
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permiss
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmi
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or at
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerab
IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 i
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advert
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfre
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Anothe
FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/r
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 an
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 an
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,
A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to
A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow
A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login
Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to ret
Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipA
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2,
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 an
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 an
OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel PO
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vul
Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthoriz
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged a
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Follow
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Genera
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding.
Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is
OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter
OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler
OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handl
Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privilege
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a
Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing a
Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the d
Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the
Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where use
Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-pr
Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize man
Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injec
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started