Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal
Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filter
Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retriev
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php),
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in ver
MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that
MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that
MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior
A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerI
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in
A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and ea
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `o
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `o
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.p
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations f
A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the f
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/Vie
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcq
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `vi
XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file
XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.
A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of t
A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/sourc
A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Recor
A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Man
Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Recor
A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag
A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file
Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1'
Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by prov
Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by pr
Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by
Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by pro
Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by pro
Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by prov
A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-serve
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing e
Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 a
A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown fun
XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local fi
A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerabili
A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started