The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of W
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.
A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted ele
A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected ele
A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid f
The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such
A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the comp
A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/
An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused
An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of O
An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to c
A segmentation violation in the oneflow._oneflow_internal.autograd.Function.FunctionCtx.mark_non_differentiable componen
GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malic
Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings
QlikView 12.50.20000.0 contains a denial of service vulnerability in the FTP server address input field that allows loca
Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affect
Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Explo
A vulnerability has been found in Open5GS up to 2.7.6. The affected element is the function sgwc_s11_handle_modify_beare
A flaw has been found in Open5GS up to 2.7.5. Impacted is the function ogs_gtp2_f_teid_to_ip of the file /sgwc/s11-handl
Stored Cross-Site Scripting (XSS) in RLE NOVA's PlanManager. This vulnerability allows an attacker to execute JavaScript
Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi
Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low pri
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-Run
A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution S
An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (Noma
An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (Noma
An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution S
A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi
A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi
A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi
Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamVie
SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the bac
Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to
A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_In
A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /r
Tanium addressed a SQL injection vulnerability in Asset.
A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown
A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionalit
A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /
soroban-sdk is a Rust SDK for Soroban contracts. Arithmetic overflow can be triggered in the `Bytes::slice`, `Vec::slice
Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.
A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi
A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillI
A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/s
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an unvalidated redirect (open redir
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-leve
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-adm
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.
A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started