ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but
Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dro
Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS
ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated
Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This a
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 wh
An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-
In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to
Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _se
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects som
A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function inp
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified agai
A vulnerability was identified in opencc JFlow up to 5badc00db382d7cb82dad231e6a866b18e0addfe. Affected by this vulnerab
A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker
A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the fil
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl
An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauth
An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an
An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these
A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system.
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo
A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown p
Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing a
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert
A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox
A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is th
A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTe
A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /Do
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file pur
A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown fun
A vulnerability was detected in Bytedesk up to 1.3.9. Affected is the function getModels of the file source-code/src/mai
A security vulnerability has been detected in Bytedesk up to 1.3.9. This impacts the function getModels of the file sour
A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /Rbacu
A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAc
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknow
A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This ma
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started