WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php.
WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified
IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another use
An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, whi
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are ins
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an
A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affec
MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This c
An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when cer
The WikiCategoryTagCloud extension is vulnerable to reflected XSS via the linkstyle attribute, which is improperly conca
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System up to 1.0. This
A vulnerability, which was classified as critical, has been found in itsourcecode Employee Management System up to 1.0.
A vulnerability classified as critical was found in itsourcecode Employee Management System up to 1.0. Affected by this
A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown f
A vulnerability was found in Campcodes Complaint Management System 1.0. It has been rated as critical. This issue affect
A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, al
The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive
lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attack
A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of sp
An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vu
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp
A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows
A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects
Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage
A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vul
A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLo
Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Im
Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access re
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil
Null pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vuln
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful e
Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this v
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started