Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Car
Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to
Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project mem
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attac
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted a
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) featur
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s hand
RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoo
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits author
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed auth
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to res
ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerabili
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Di
ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and fa
ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS r
NVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disc
OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allo
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
coursevault-preview is a utility for previewing course material files from a configured directory. coursevault-preview v
QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file prev
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() func
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /t
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repe
Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from
yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Acco
The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically w
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, Mustache navigation templates interpolated configu
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand:
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() int
Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vul
FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter
An issue that could allow a credential to be updated and used for a task from outside of the authorized organization sco
An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved.
An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields
An issue that allowed administrators to create and update users outside of their authorized organization scope has been
An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolve
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started