A vulnerability classified as problematic was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f61
The Memory Usage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. It has been rated as c
LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present i
A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affecte
A vulnerability was found in Canara ai1 Mobile Banking App 3.6.23 on Android and classified as problematic. This issue a
A vulnerability classified as critical has been found in Jingmen Zeyou Large File Upload Control up to 6.3. Affected is
A vulnerability, which was classified as critical, has been found in Campcodes Courier Management System 1.0. This issue
A vulnerability classified as critical was found in Campcodes Courier Management System 1.0. This vulnerability affects
A vulnerability classified as critical has been found in Campcodes Courier Management System 1.0. This affects an unknow
A vulnerability was found in Campcodes Courier Management System 1.0. It has been rated as critical. Affected by this is
A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. Affected by this
A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unkno
The Educenter theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Circle Counter Block in all versi
The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6.
The Wonder Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image title and description
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'
A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the funct
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to vers
A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown p
A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some
A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System 1.0. Affected is
A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This
A vulnerability was found in code-projects Food Review System 1.0 and classified as critical. This issue affects some un
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) all
A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affe
A vulnerability, which was classified as critical, was found in deerwms deer-wms-2 up to 3.3. This affects an unknown pa
A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length
A vulnerability, which was classified as critical, has been found in deerwms deer-wms-2 up to 3.3. Affected by this issu
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. Affected by this vulnerability is an u
Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the privileges of other user accou
Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via t
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog p
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerabil
A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scrip
Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.
Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauth
In the Linux kernel, the following vulnerability has been resolved: drm/exynos: exynos7_drm_decon: add vblank check in
In the Linux kernel, the following vulnerability has been resolved: netlink: Fix wraparounds of sk->sk_rmem_alloc. Net
In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} TOCTOU vsock_find_c
In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix NULL pointer dereference in vcc_send
In the Linux kernel, the following vulnerability has been resolved: net/sched: Abort __tc_modify_qdisc if parent class
In the Linux kernel, the following vulnerability has been resolved: ALSA: ad1816a: Fix potential NULL pointer deref in
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: rtsn: Fix a null pointer dereference
In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix GPF in bitmap_get_stats() The co
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: prevent NULL pointer dereferenc
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix race condition in TTY wa
In the Linux kernel, the following vulnerability has been resolved: raid10: cleanup memleak at raid10_make_request If
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started