A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web
A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf
Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 all
Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate
agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the
StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.
Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users.
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro
melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability
A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function ht
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are e
An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP re
Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. T
A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the fun
Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites
An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions loggi
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version
The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F
The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi
The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin
The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis
The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ paramete
The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ param
The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘w
The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location
The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_b
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based
The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve
The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure
The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all
A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the functi
A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file mod
A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown fu
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects
NVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive informat
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. This
An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with e
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started