SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vuln
A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file interna
ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local at
BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local
BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration paramete
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplyi
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplyi
RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local
RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash
A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/tex
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the
i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensi
SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arb
Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files an
A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file
NordVPN 6.19.6 contains a denial of service vulnerability that allows local attackers to crash the application by submit
MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by op
RealTerm Serial Terminal 2.0.0.70 contains a denial of service vulnerability that allows local attackers to crash the ap
RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allow
Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that al
TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the
Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability in the Serial Code registration field that allows
PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by
PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by
jetAudio 8.1.7 contains a buffer overflow vulnerability in the video converter component that allows local attackers to
Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by sup
SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local atta
Selfie Studio 2.17 contains a denial of service vulnerability in the Resize Image function that allows local attackers t
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the applic
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows lo
Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the applica
CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the applicatio
Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supply
Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputti
VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the applicatio
BlueStacks 4.80.0.1060 contains a denial of service vulnerability that allows local attackers to crash the application b
NetAware 1.20 contains a buffer overflow vulnerability in the User Blocking feature that allows local attackers to crash
NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the
Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the applic
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providi
A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the
A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/ad
A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the fi
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src
A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function
The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings
The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started