Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu
Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V
In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firm
python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerab
Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra
A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Opt
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected
A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_
A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown fu
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Softwa
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forc
Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affe
Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing
The credentials of the users stored in the system's local database can be used for the log in, making it possible for an
JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerab
A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, mak
It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.
The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short
For failed login attempts, the application returns different error messages depending on whether the login failed due to
Multiple endpoints with sensitive information do not require authentication, making the application susceptible to infor
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be s
The application provides access to a login protected H2 database for caching purposes. The username is prefil
If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and metho
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making t
The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modificatio
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sa
A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown functi
A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function up
A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16
A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the
A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown function
A vulnerability was detected in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/mp. Performi
A vulnerability was determined in Belkin F9K1015 1.00.10. Impacted is an unknown function of the file /goform/formSetWan
A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetS
A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts a
A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret H
A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and h
A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi
A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controlle
A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the
A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ o
A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing
A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternR
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started