The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in a
Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.
An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 b
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple P
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with p
Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with p
Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to in
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.
Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 an
A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.
A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers
vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticat
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauth
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated use
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a sp
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recomm
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom In
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing. This iss
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP h
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local use
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in th
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3
The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_styleshe
Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1.
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functio
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functi
SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be execute
The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetw
The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and includ
The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all ver
The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1
The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forg
The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in a
HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu
A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu
A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions pr
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started