The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all version
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s
When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadver
When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the pu
A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability
A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data d
A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown functio
A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown funct
A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul
Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Op
The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the
Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (S
Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnera
Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing u
Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage fu
V-SOL GPON/EPON OLT Platform v2.03 contains multiple reflected cross-site scripting vulnerabilities due to improper inpu
Yahei-PHP Prober 0.4.7 contains a remote HTML injection vulnerability that allows attackers to execute arbitrary HTML co
FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to i
FaceSentry Access Control System 6.4.8 contains a cross-site scripting vulnerability in the 'msg' parameter of pluginIns
SOCA Access Control System 180612 contains a cross-site scripting vulnerability in the 'senddata' POST parameter of logg
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attac
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows una
REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions ca
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a P
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacke
A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of t
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
The Report Builder component of the application stores user input directly in a web page and displays it to other users,
The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed g
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when que
MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vend
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started