The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in a
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_conte
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs
Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) att
TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows
TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy address configuration that allows
AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attac
AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by
AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder
Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administrat
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2,
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in th
Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direc
NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown conte
Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an
DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access co
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node'
PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeratio
SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control config
A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown funct
time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any t
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below th
A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /gofo
A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/
client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Vers
Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profil
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an au
A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file
Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using p
OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was d
OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an a
OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via p
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/conte
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attac
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox Centr
Millhouse-Project 1.414 contains a persistent cross-site scripting vulnerability in the comment submission functionality
html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scrip
A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an u
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started