A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLit
A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Le
A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow
Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Referenc
An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Saf
DiracX-Web is a web application that provides an interface to interact with the DiracX services. Prior to version 0.1.0-
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d
Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed be
Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated fr
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p
The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-a
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate
A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (E
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including
Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit
Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including
A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attac
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including
Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is gene
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (clien
Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net:
Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situati
Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploitin
Missing Authorization vulnerability in alexvtn Internal Linking of Related Contents internal-linking-of-related-contents
Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Exploiting In
Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrect
Missing Authorization vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocomme
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins LightBox
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon
Missing Authorization vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Exploiting Incorrectly Con
Cross-Site Request Forgery (CSRF) vulnerability in Xfinitysoft WP Post Hide wp-post-hide allows Cross Site Request Forge
Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Animator scroll-triggered-animations allows Cross Site
Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cr
Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started