MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs curren
Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category
Chamilo is a learning management system. Prior to version 1.11.34, a stored XSS vulnerability exists in Chamilo LMS that
A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unkno
A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown funct
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure
Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Prot
Sensitive information disclosure due to improper configuration of a headless browser. The following products are affecte
Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyb
Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Prot
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acr
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Pro
Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acron
Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cybe
Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi
OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget
OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that al
OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during ins
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS
OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching acc
OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attacke
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in
OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydr
OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi
OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled)
OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src
OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /ap
OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extensi
OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attacke
Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to ver
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async,
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started