A vulnerability was found in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /Online
A flaw has been found in SourceCodester/jkev Record Management System 1.0. Affected by this issue is some unknown functi
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function del
A security flaw has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This affects an unknown function. P
A vulnerability was identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The impacted element is an unknown funct
A security flaw has been discovered in AutohomeCorp frostmourne up to 1.0. Affected is the function httpTest of the file
A vulnerability was determined in Campcodes Complete POS Management and Inventory System up to 4.0.6. This affects an un
A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function
A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _
A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function
A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file pa
A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function dis
A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown
A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown process
A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionali
A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of t
A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson
A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected elem
A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /
A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been re
A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember
A vulnerability was detected in QingdaoU OnlineJudge up to 1.6.1. Affected by this issue is the function service_url of
A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the functio
A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtil
A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packa
A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sand
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function o
A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the
A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown par
A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown fu
Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative
Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local att
FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by in
MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to in
MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script p
Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by su
FastTube 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by subm
One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by su
Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submit
Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by sub
VSCO 1.1.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitti
Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credenti
NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to c
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres
The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulner
The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started