A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape
Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque
When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo
A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedEle
A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tool
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file s
A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Store
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi
The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-
The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, all
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated
The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API route
The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use
A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of
A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBg
A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function P
A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functiona
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and
A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the fi
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the
A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des
Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user
boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl
Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al
IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path t
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started