Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di
A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst
Transient DOS when processing a received frame with an excessively large authentication information element.
Memory corruption while calculating offset from partition start point.
Memory corruption when calculating oversized partition sizes without proper checks.
IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violatio
A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pre
An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pr
A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles r
A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocat
A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork
The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead
In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p
In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if
In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attac
Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacke
The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, whi
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/ap
A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. Th
A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncl
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the f
A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the
A flaw has been found in Open5GS up to 2.7.6. The impacted element is the function sgwc_tunnel_add of the file /src/sgwc
A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function sgwc_s5c_handle_create_bearer_
A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_create_indir
A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the
A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file
A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /
QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to in
Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Nam
WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject
Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths w
Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malic
BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious
Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to i
Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote at
Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipula
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started