IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the fa
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticat
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticat
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthentic
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 th
A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patien
A flaw has been found in RemoteClinic up to 2.0. This vulnerability affects unknown code of the file /staff/edit.php. Ex
A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng
A vulnerability was identified in itsourcecode Sports Management System 1.0. This impacts an unknown function of the fil
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil
In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of s
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/m
A vulnerability was identified in deepakmisal24 Chemical Inventory Management System up to 1.0. Affected by this vulnera
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administra
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attacke
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attacke
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attacke
A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/
A vulnerability has been found in Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24.
A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controlle
A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function o
A vulnerability was identified in DCMTK up to 3.6.9. This affects an unknown function in the library dcmimage/include/dc
A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/templat
A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the fil
The Amministrazione Trasparente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in
A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some
A flaw has been found in SourceCodester Advanced School Management System 1.0. This affects an unknown function of the f
A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown
A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_vie
A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Hi
A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the
A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /m
A vulnerability was determined in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Formu
The TablePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode_debug’ parameter in
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library short
The Related Posts Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress allows Path Traversal.This
Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next()
Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to bef
Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to bef
A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown functi
A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidMa
A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file
A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functio
Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect
nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1
A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started