An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Jun
A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insig
ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has b
A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELES
An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside
A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) v
A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious
A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS
Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the applicati
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listin
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to e
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Iden
A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) vi
A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (D
A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafte
Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary
Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads th
Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that
Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl par
RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to
Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, cu
ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows re
AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by
AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by
MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH conne
Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settin
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogX
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para
An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro
Certain error messages returned by the application expose internal system details that should not be visible to end user
The application discloses all used components, versions and license information to unauthenticated actors, giving attack
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft throu
The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to
The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending du
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions thr
Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.
An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without
An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing
An attacker with limited permissions may still be able to write files to specific locations on the device, potentially l
Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead
Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authenticatio
Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover cre
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Chec
A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads wh
A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user t
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started