A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/
Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out o
Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially se
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when proces
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub
A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo
JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj
A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated,
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low
A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a
A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You
Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26
Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin
The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u
Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A
Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly
Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec
Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Co
Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started