Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} an
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to
A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMess
A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_nul
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification w
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed
A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. U
A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the
A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Execut
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat
The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication att
A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attac
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A l
SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobpor
A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/C
A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown functi
A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown funct
In the Linux kernel, the following vulnerability has been resolved: igb: remove napi_synchronize() in igb_down() When
In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc()
In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Comm
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulne
A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the f
A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v
A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php v
A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the do
A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a dire
An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to
A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is
A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of th
ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionali
ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() fu
ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php
ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint tha
A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of t
A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile o
SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints t
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versio
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected
A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an u
A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the f
A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown pro
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to c
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem
A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code
A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file
A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of th
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started