Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forg
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occ
ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementa
An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predict
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0,
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0,
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3
Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerabilit
An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package
A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote at
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to co
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encrypt
A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attac
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti
Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra
Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an
OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file
The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumer
A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerabil
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input vali
Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Sc
A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution a
OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that al
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validati
A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contai
Lack of output escaping for article titles leads to XSS vectors in various locations.
Lack of output escaping leads to a XSS vector in the multilingual associations component.
A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the fil
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large v
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force U
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix differential encoding verification D
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix: limit the number of levels of policy
In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with it
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix memory leak in verify_header The fun
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Only WARN in direct MMUs when overwri
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even w
A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the
PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access cou
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started