Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.
Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registratio
User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overf
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage
The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface
Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.
Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_T
Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs
Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf
Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp
The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. W
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_creat
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngim
Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing al
Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un
Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow
Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application b
A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to me
A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of inte
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modif
A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged proces
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: befor
Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execut
Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injec
The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to
go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repositor
Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated u
Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` pre
pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `p
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it f
EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequen
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicio
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows mali
A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability
A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min
A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client
A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by ca
A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page —
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode
Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An att
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started