A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGr
A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the compone
A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file applicat
A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/l
The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi
The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `s
The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes
The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working
The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget
The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via exter
gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT
The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all
The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in al
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) rende
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation com
Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerabi
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulner
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the
The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2
Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATC
Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in Ki
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in Abs
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new in
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (c
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template en
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style
OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is co
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 thro
xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary comma
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul
Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication,
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and ses
Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing c
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/R
xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its log
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-drive
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the Clum
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started