Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.
This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulne
ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9
Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resourc
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun
Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding:
Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length valu
Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Co
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the
Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to ex
Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backs
Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration?
Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal
Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated
Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cau
A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which
Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload
Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML
Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.
Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content
A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does
The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions
A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverr
A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeen
A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_proce
A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/l
A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unkno
A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::
A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unk
A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file
A security flaw has been discovered in CesiumGS CesiumJS up to 1.137.0. Affected by this issue is some unknown functiona
The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could all
The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated us
A vulnerability was determined in itsourcecode University Management System 1.0. Affected by this vulnerability is an un
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the fil
A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of th
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification triggering d
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 1
A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the
A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createOb
A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the fu
A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when confi
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started