In MAE, there is a possible system crash due to use after free. This could lead to local denial of service if a maliciou
In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local infor
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalati
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d
A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps
A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file
A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the fi
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows script injection via forum URL data
wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve priva
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wp
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge,
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reo
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or u
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T
The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentati
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an ou
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim'
Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds r
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(
malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability
PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report for
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functional
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows upl
HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code i
HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulner
Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can stor
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its man
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for sessio
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started