An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization
An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows aut
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Pa
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote a
Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkm
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in it
Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker
Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Secur
Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiti
Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul
The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queri
The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated
The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function be
Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operati
In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of serv
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE ha
A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite ar
A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown f
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The re
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the
The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulner
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint s
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL end
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPE
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerabl
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vuln
Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a
OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthe
A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter o
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inj
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts)
lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML in
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file
A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the functi
Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed l
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started