Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control
Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments
During the brief window between installation and the first administrator login, remote attackers may exploit the default
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user
A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of
A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c.
A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src
Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.
Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack.
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. T
Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially result
Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the conten
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the cont
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and all
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitra
A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_pack
nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engine
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ow
An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter
A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q
A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects un
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the conte
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when vis
Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimiza
An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows
A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 t
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through
IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vu
HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the funct
A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cg
qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability e
A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/se
Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer
Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable t
In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKe
In the Linux kernel, the following vulnerability has been resolved: staging: gpib: fix unset padding field copy back to
In the Linux kernel, the following vulnerability has been resolved: staging: fbtft: fix potential memory leak in fbtft_
In the Linux kernel, the following vulnerability has been resolved: powercap: dtpm_cpu: Fix NULL pointer dereference in
In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Check governor before using governor-
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid accessing uninitialized arvif->
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Pass ab pointer directly to ath12k_dp
In the Linux kernel, the following vulnerability has been resolved: iwlwifi: Add missing check for alloc_ordered_workqu
In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop2: fail cleanly if missing a prima
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started