A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check
A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the fil
A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown funct
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown functi
A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacM
A vulnerability was identified in code-projects Employee Management System 1.0. This affects an unknown part of the file
A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown f
A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the fi
A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in
Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address informati
A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown
A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl
A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of th
A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/s
A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function q
A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unkn
There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded,
A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file bac
A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSp
A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=cust
A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=
Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplyin
P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows
ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the applica
Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to
Bome Restorator 1793 contains a buffer overflow vulnerability that allows local attackers to crash the application by su
Project64 2.3.2 contains a buffer overflow vulnerability in the Plugin Directory settings field that allows local attack
Easyboot 6.6.0 contains a buffer overflow vulnerability in the Replace Text function that allows local attackers to cras
Softdisk 3.0.3 contains a buffer overflow vulnerability in the registration code dialog that allows local attackers to c
StyleWriter 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplyi
Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application b
Easy PhotoResQ 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supp
Fathom 2.4 contains a buffer overflow vulnerability in the Authorization Code field that allows local attackers to crash
HD Tune Pro 5.70 contains a buffer overflow vulnerability that allows local attackers to crash the application by supply
Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing
iCash 7.6.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying a
Infiltrator Network Security Scanner 4.6 contains a buffer overflow vulnerability that allows local attackers to crash t
jiNa OCR Image to Text 1.0 contains a denial of service vulnerability that allows local attackers to crash the applicati
PicaJet FX 2.6.5 contains a denial of service vulnerability that allows local attackers to crash the application by subm
PixGPS 1.1.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying
RoboImport 1.2.0.72 contains a denial of service vulnerability that allows local attackers to crash the application by s
Faleemi Plus 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supp
InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by im
CrossFont 7.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by submittin
TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to cra
A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of t
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component
A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unk
A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function Execut
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started