OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi
oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and
A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0 and classified as problematic. This issue affects some unkno
A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnera
A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter
A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authent
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l
The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and u
The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryp
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authent
A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is t
Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR R
The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does
Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is explo
Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is e
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the
A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unkn
A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as criti
A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving Syst
A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving
A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This
Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulner
A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0.
A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critic
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while par
In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer wh
In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer whil
A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function Stdi
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used
An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access in
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php
Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the ses
Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the pas
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Se
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated u
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configu
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credenti
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authent
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d
OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started