ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA librari
ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification setti
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for m
Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows
Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a
Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add n
Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025
A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the l
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, includi
A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown f
A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save
Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL pa
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject maliciou
Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious S
Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts wh
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload m
NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attacker
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with
SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a cr
Inventory Management System 1 was discovered to contain a SQL injection vulnerability.
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present i
IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM De
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration pri
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attac
An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for proc
The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an export
A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attacker
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management Syste
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext t
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext thro
TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_
TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.
An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in
grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data d
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a
The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu
The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorizatio
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the ident
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tok
A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secr
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started