The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_pro
Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Script
A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/v
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be h
TypiCMS is a multilingual content management system based on the Laravel framework. A Stored Cross-Site Scripting (XSS)
Repostat is a React component to fetch and display GitHub repository info. Prior to version 1.0.1, the `RepoCard` compon
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitac
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
A security vulnerability has been detected in CodeAstro Food Ordering System 1.0. This affects an unknown function of th
Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG`
OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.
GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access an
Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an au
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input During Web Page Gener
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to acc
Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin pr
NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys
Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (def
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protections for state-changing
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the we
Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the fil
A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping
WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video comments and uses P
Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SS
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to impr
The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before us
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148
Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started