Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that
Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can in
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attack
PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-b
PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer derefere
In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comme
The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its genera
The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutr
MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML.
PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /c
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to per
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoo
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attac
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft E
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0,
aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the hand
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext
Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce
Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v
Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed)
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not
A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper t
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software I
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Sof
The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' confi
xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript v
Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site na
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes l
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fi
SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the N
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where cr
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 126,669 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started