NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack
The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass th
A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown fun
A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file
The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before
The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configur
A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unkn
A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.ph
A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php.
A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /ad
A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of t
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd o
A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects u
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all
A vulnerability was determined in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown
A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functi
A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /a
A flaw has been found in itsourcecode COVID Tracking System 1.0. This impacts an unknown function of the file /admin/?pa
A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This affects an unknown function of the file /ad
A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown fun
A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removef
A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by t
A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3.
A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and
The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing c
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized mod
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u
The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote u
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows
The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak info
SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to
Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is f
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with th
IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.
Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linu
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to befo
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to befo
Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting
A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries,
The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via
Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise w
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started