A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-size
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid
In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_rang
Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrec
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi
A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send a
A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel
A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs
A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at
A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri
The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter
The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as c
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect
Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun
A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi
The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm
LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct
OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack
OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi
OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowe
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon
OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow
OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allo
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str
OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars
OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows
OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth
Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a u
Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic
IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou
A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att
Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_na
Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remot
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing an
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started