IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to c
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by exe
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific con
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service a
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, Psy
Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer au
A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of
A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/m
A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /b
OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description
Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicio
Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote at
Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module th
Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and p
PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly
Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows at
Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenti
ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) v
A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /
A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSess
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the fi
Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-s
Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can
Improper handling of filenames in certain HIKSEMI NAS products may lead to the exposure of sensitive system files.
Due to inadequate access control, authenticated users of certain HIKSEMI NAS products can manipulate other users' file r
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no
A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Re
Tanium addressed an improper access controls vulnerability in Tanium Server.
A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZ
TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`,
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.1
A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boa
A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the
A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin
Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authent
birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att
FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload S
A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of
Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code.
Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application
Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co
Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started