A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature.
A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonli
A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A
A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A cra
A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of th
A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validat
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch
There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of
There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of auth
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-fo
Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows d
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive
Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the imprope
A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the
The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches
A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows rem
The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HT
A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon
A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of
A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file je
A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown functi
A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the f
A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of
A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown functi
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated use
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user t
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated use
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excess
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated
Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbea
Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the
Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence o
A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remot
A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute ar
A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An
BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker c
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions
Advantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the ex
Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system t
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary
Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. Th
A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unkno
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started