IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK,
A Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated at
Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic
The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim.
traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists wh
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to exec
SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fie
SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly hand
A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.p
A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.p
A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the se
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were disco
Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were disco
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discov
Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.8
In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value
Race Condition in the Directory Validation Logic in the TeamViewer Full Client and Host prior version 15.69 on Windows a
An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.
Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Contro
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a
The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Di
The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on
A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file s
A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/
A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. A
A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by t
A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected
A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/use
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admi
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation
A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality
A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processi
File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw al
A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c
A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the fi
A flaw has been found in lostvip-com ruoyi-go up to 2.1. This impacts the function SelectListByPage of the file modules/
A vulnerability was detected in lostvip-com ruoyi-go up to 2.1. This affects the function SelectListByPage of the file m
A security vulnerability has been detected in lostvip-com ruoyi-go up to 2.1. The impacted element is the function Selec
A weakness has been identified in lostvip-com ruoyi-go up to 2.1. The affected element is the function SelectListByPage
A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUplo
Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code
The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local sto
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.
Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due
DASAN GPON ONU H660WM H660WMR210825 is susceptible to improper access control under its default settings. Attackers can
DASAN GPON ONU H660WM OS version H660WMR210825 Hardware version DS-E5-583-A1 was discovered to contain insecure default
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started