Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of
LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Req
LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execu
OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vuln
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of th
BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received wi
Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operat
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive info
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite a
A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could all
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could a
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow
A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local atta
A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated
A security flaw has been discovered in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This affects an unknown part of the
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown f
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyn
zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and inclu
A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unk
A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build confi
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption heade
The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forger
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting
The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all ve
The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current
The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi
A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function fil
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP ser
A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part o
A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown fun
changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-wat
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This i
A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file lib
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started