pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServ
mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in serv
An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length
FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_
FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the
The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes
APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. Reso
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is suppl
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication m
An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capt
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatic
Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a control
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is expose
Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read a
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connecti
Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: thr
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syW
HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the paren
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the fi
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of t
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Techno
Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Fu
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validat
The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one
The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sal
The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in a
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its bac
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these m
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — fu
The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an at
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configure
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a con
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue ap
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for examp
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes di
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deser
SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators,
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started