WebMO Job Manager 20.0 contains a cross-site scripting vulnerability in search parameters that allows remote attackers t
Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Atta
Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote atta
PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted paramete
PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users
PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and
Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. A
Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remo
Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment in
Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword
The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1
In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_periph
In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak of flow steer list on rmmod
In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak in idpf_vport_rel() Free vpo
In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak in idpf_vc_core_deinit() Mak
In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: fix memory leak in update_eth_re
In the Linux kernel, the following vulnerability has been resolved: net: 3com: 3c59x: fix possible null dereference in
In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix NULL dereference on dev
In the Linux kernel, the following vulnerability has been resolved: btrfs: release path before initializing extent tree
In the Linux kernel, the following vulnerability has been resolved: idpf: fix error handling in the init_task on load
In the Linux kernel, the following vulnerability has been resolved: inet: frags: drop fraglist conntrack references Ja
In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: fix reference leak in gpio_mpsse_probe
In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlat
In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe
In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route al
In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route
In the Linux kernel, the following vulnerability has been resolved: dmaengine: sh: rz-dmac: fix device leak on probe fa
In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route
In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: dma-crossbar: fix device leak on am3
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix NULL dereference on root when tracing in
In the Linux kernel, the following vulnerability has been resolved: can: j1939: make j1939_session_activate() fail if d
In the Linux kernel, the following vulnerability has been resolved: rust_binder: remove spin_lock() in rust_shrink_free
In the Linux kernel, the following vulnerability has been resolved: counter: interrupt-cnt: Drop IRQF_NO_THREAD flag A
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the
The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access o
The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi
Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensi
Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attacke
OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can
Sickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by s
LocalSend is a free, open-source app that allows users to share files and messages with nearby devices over their local
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a de
IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started