A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionalit
Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanit
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres
The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to gener
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which c
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft
Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in
Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests us
NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.inter
NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to Reflected XSS through its ui.add_css,
Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated a
Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Comm
Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Comm
Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon
Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versio
Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.17624313
IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts whe
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive in
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated us
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of te
A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This ma
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are af
Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuratio
A stored cross-site scripting (XSS) vulnerability exists in the web interface of Lyrion Music Server <= 9.0.3. An authen
Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration
Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corru
In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check
In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo
A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functiona
A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to e
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level priv
A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patche
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisio
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti
In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead
In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to
In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due
In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in
In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. Thi
In multiple locations, there is a possible way to read files from another user due to a missing permission check. This c
In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion.
In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead
In multiple files, there is a possible way to reveal information across users due to a missing permission check. This co
In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy
In multiple locations, there is a possible way to read files from another user due to a missing permission check. This c
In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started