IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes
Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the
IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNI
A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient
The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unautho
Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute
Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary
AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image
A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /a
An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data an
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2
An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback
A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknow
An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/
There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c938116
A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a us
A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an admi
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an admin
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a
A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gain
A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the
A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php.
A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_
A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknow
A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /
A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processi
A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function dele
Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. W
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host
ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature i
The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capabili
The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all
ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is v
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 thro
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct
kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack a
OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vul
A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extra
A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout p
Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing
The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to ba
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below,
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started