A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control S
The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local att
Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability.
Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an ou
A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file r
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCa
A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function o
A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the fi
A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated re
Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positione
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of
A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.
A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of t
A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boo
A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allow
OpenClaw before 2026.4.8 contains a remote code execution vulnerability caused by missing environment variable denylist
OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channe
OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared ga
OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing
OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure become
OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host e
OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local f
OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An
OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limi
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restri
OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authen
OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebS
OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic lo
OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries th
OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted a
OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust
OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execut
OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array s
OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get me
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers
OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attac
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure
OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling th
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints t
OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowin
OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary en
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could
NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A
Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The
An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started