A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been declared as critical. Affect
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. Affe
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. This issue af
A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and cl
A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f71
A vulnerability classified as critical has been found in PHPGurukul Vehicle Parking Management System 1.13. Affected is
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been declared as critical. This v
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This
A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected
A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This is
IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due t
The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_aj
The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via th
A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensit
A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can per
Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized
Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many e
An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process termi
A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as cr
haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a us
A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the functi
Microsoft Edge (Chromium-based) Spoofing Vulnerability
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a netw
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step proc
Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthen
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allow
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI o
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Netwo
A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an
A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-
gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value.
A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolv
An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-pri
A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolv
An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS
An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos
An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on M
A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Net
An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Netwo
An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specifi
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with comm
An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in cale
An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp
The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started