In the Linux kernel, the following vulnerability has been resolved: cxl: fix possible null-ptr-deref in cxl_pci_init_af
In the Linux kernel, the following vulnerability has been resolved: drivers: net: qlcnic: Fix potential memory leak in
In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Fix crash on isr after kexec() If
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint comma
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported version
Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to caus
A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /
A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to
Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronizat
A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A
During a short time frame while the device is booting an unauthenticated remote attacker can send traffic to unauthorize
A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some unknown processing of the
A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of t
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown fun
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program th
O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery vulnerability, allowing unauthent
A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Affected by this vulnerability is a
A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknow
A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function
A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the fun
A flaw has been found in SourceCodester Student Grading System 1.0. This vulnerability affects unknown code of the file
A vulnerability was detected in SourceCodester Student Grading System 1.0. This affects an unknown part of the file /for
A security vulnerability has been detected in SourceCodester Student Grading System 1.0. Affected by this issue is some
A weakness has been identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknow
The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth
A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affect
A security vulnerability has been detected in SourceCodester Link Status Checker 1.0. This vulnerability affects unknown
A weakness has been identified in SourceCodester Student Grading System 1.0. This affects an unknown part of the file /r
A security flaw has been discovered in SourceCodester Student Grading System 1.0. Affected by this issue is some unknown
A vulnerability was identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknow
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp
A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /g
A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Impacted is an unknown
IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could all
A weakness has been identified in Korzh EasyQuery up to 7.4.0. This issue affects some unknown processing of the file /a
A security flaw has been discovered in fcba_zzm ics-park Smart Park Management System 2.0. This vulnerability affects un
A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Ha
A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of
A vulnerability has been found in fcba_zzm ics-park Smart Park Management System 2.0. Affected is an unknown function of
A flaw has been found in miurla morphic up to 0.4.5. This impacts the function fetchHtml of the file /api/advanced-searc
A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the
A weakness has been identified in CRMEB up to 5.6.1. The affected element is the function editAddress of the file app/se
A security flaw has been discovered in CRMEB up to 5.6.1. Impacted is the function Save of the file app/services/system/
A vulnerability was determined in codesiddhant Jasmin Ransomware up to 1.0.1. This vulnerability affects unknown code of
A vulnerability was found in Yida ECMS Consulting Enterprise Management System 1.0. This affects an unknown part of the
A flaw has been found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of
A flaw has been found in cdevroe unmark up to 1.9.3. This vulnerability affects unknown code of the file application/vie
A vulnerability was detected in cdevroe unmark up to 1.9.3. This affects an unknown part of the file /application/contro
A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unkn
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started