Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Impro
A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delst
The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts)
Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain poten
Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-o
Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain p
Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of d
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pag
The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript ch
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resour
The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, ann
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions,
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. A
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can in
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects C
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does
A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `s
A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of
A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache o
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D
SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function i
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before vers
Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From
The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before vers
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started