Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supp
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025
code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php.
Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search pa
The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files
The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB
Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application impl
Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could
ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is
LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can
HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the
Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.
Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifia
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1,
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1,
Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to
Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability
Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An
Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.
daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.
daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.
Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code
Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Perfor
Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Perf
Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Per
Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.
Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application
Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter
A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Info
SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using
Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i
Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver
There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerabilit
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started