An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub
Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, use
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all
A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected
A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to,
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of
A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an
A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could al
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting
Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malici
Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malform
A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwri
Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a maliciou
Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesse
A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9. Affected is an unknown funct
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9. This issue affects some
A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9. This affects an unknown part of the
A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some u
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’
A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue
A vulnerability classified as critical was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7.
A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticF
A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function
A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic.
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client
A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attac
GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19
GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1
ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file con
playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability.
andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability.
A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability ar
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Refe
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Partie
Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerP
An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction
A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitr
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute ar
UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 an
** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affe
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory relea
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started