A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the
Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA
A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built wi
Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same l
Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET re
A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is
The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver
An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them m
Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden g
A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certa
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially
An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings
A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information fr
Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive u
A flaw was found in the course overview output function where user access permissions were not fully enforced. This coul
Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated atta
Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du
QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with adm
QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin p
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner S
Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted in
Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path
Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored b
GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within t
Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Comm
Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated us
Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to e
Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privil
Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initial
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not
FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link i
Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 20
A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Porta
A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file
Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of othe
Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an act
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started