Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe
Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notifica
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in en
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions
Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul
Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by auth
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back
Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an
Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to ac
Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affe
A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corrupti
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elem
Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Secur
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incor
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elem
Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Co
Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGr
Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Log
Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150,
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM
An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When
Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a Requ
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0.
Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_m
Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modu
Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth
Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbi
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces author
Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker
Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php
Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not vali
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execut
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1.
ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the l
OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In ver
OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlie
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created f
OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars e
Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated vers
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started