In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of direct
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed af
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 thr
Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, cr
A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file Andr
Missing Authorization vulnerability in frenify Categorify categorify allows Exploiting Incorrectly Configured Access Con
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLento
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 D
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Dolson My Tick
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Addition
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welca
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Incl
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline'
Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker
Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Acc
Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control S
Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Inco
Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Ser
Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker
Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Re
A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter confi
A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Vir
A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of P
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabilit
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that cou
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized
Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started