Tanium addressed an incorrect default permissions vulnerability in Enforce.
Tanium addressed an improper access controls vulnerability in Reputation.
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
Tanium addressed an incorrect default permissions vulnerability in Comply.
Tanium addressed an incorrect default permissions vulnerability in Discover.
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
Tanium addressed an incorrect default permissions vulnerability in Patch.
Tanium addressed an incorrect default permissions vulnerability in Performance.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
Tanium addressed an improper access controls vulnerability in Deploy.
Tanium addressed an improper access controls vulnerability in Patch.
Tanium addressed an improper input validation vulnerability in Discover.
Tanium addressed a documentation issue in Engage.
Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which
The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is get
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provide
A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption o
Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipu
Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipu
A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i
Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account pre
PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The ap
HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrativ
Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized a
Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers t
PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attacke
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allow
Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash t
ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by l
Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause
CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriti
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data due
IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM
IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th
In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password
A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block.
The Peter's Date Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a
The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored C
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi
web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vu
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started