Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may r
The Dynamic Widget Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget content fiel
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'load
The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-a
A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/m
A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMig
A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the com
A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site script
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks.
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mas
Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin ur
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc
A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file model
A weakness has been identified in ZenTao up to 21.7.6-85642. The impacted element is the function fetchHook of the file
IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO
IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impe
IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Priv
Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas:
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Pri
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Group invite allows Forceful Browsing.This
IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper
IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able
IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the syste
OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allow
melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacke
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing /
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can
n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vu
n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final co
In the Linux kernel, the following vulnerability has been resolved: fs/writeback: skip AS_NO_DATA_INTEGRITY mappings in
In the Linux kernel, the following vulnerability has been resolved: can: usb_8dev: usb_8dev_read_bulk_callback(): fix U
In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: signal: Allocate SSVE storage when re
In the Linux kernel, the following vulnerability has been resolved: timekeeping: Adjust the leap state for the correct
In the Linux kernel, the following vulnerability has been resolved: ice: fix devlink reload call trace Commit 4da71a77
In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started