Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.
HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ce
Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request
A vulnerability has been found in birkir prime up to 0.4.0.beta.0. The affected element is an unknown function of the fi
A flaw has been found in birkir prime up to 0.4.0.beta.0. Impacted is an unknown function of the file /graphql of the co
Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to
OpenProject is an open-source, web-based project management software. When using groups in OpenProject to manage users,
OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and
A vulnerability was detected in birkir prime up to 0.4.0.beta.0. This issue affects some unknown processing of the file
A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code.
An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Run
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm
A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modul
A vulnerability was detected in technical-laohu mpay up to 1.2.4. This affects an unknown function. Performing a manipul
A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown funct
A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg o
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg
A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This v
A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_
A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records t
A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c o
A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performi
A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /a
A security flaw has been discovered in itsourcecode Society Management System 1.0. This impacts an unknown function of t
A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown function of the fi
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to
A vulnerability was determined in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_downlink_data_notificati
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XS
Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a
1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulne
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerabili
A security vulnerability has been detected in lwj flow up to a3d2fe8133db9d3b50fda4f66f68634640344641. This affects the
A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file
A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::stri
A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSeg
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-t
A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the function LoadFontData of t
A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/pub
A flaw has been found in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. This affects the function rtsp_p
A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageF
A vulnerability was detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The impacted element is t
A security vulnerability has been detected in cijliu librtsp up to 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The affecte
A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.p
A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of th
A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /
A vulnerability was found in bastillion-io Bastillion up to 4.0.1. This issue affects some unknown processing of the fil
A vulnerability has been found in bastillion-io Bastillion up to 4.0.1. This vulnerability affects unknown code of the f
A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lh
A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file s
A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started