Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to
A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the
A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the func
A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/pr
A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/expor
A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unkno
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artif
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the func
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows auth
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows una
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoo
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged use
A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this
libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10
Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can
Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `
Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable
A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown functi
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share toke
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other toke
CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retr
A vulnerability was identified in Daptin 0.10.3. Affected by this vulnerability is the function goqu.L of the file serve
Plane is an an open-source project management tool. In plane.io, a guest user doesn't have a permission to access https[
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator
An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user accoun
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit th
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote atta
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating
A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web script
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started