AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes appl
Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attacker
Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for exte
Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo p
e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload ma
Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to re
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulat
Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows atta
VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate d
Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr
YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts throug
YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrar
WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attac
NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by othe
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to
Substance3D - Modeler versions 1.22.4 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to
Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could le
Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could le
Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (C
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-1
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-1
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service thr
A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (R
Substance3D - Designer versions 15.0.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead t
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't val
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data
An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin
A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject s
openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vul
Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead t
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bounds Read vulnerability that could lead t
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validat
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching ex
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to eleva
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker
Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose informat
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started