n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /re
SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key
Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enable
Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to sal
Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Sc
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName paramete
ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, reg
n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/bina
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Guten
Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting I
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScrip
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto librar
The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, th
The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password
All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta
The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitti
The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such
The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. The
For failed login attempts, the application returns different error messages depending on whether the login failed due to
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to esta
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject
Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.
Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups li
In the Linux kernel, the following vulnerability has been resolved: power: supply: max77705: Fix workqueue error handli
In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Discard stale CPU state when handling
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: handle hdr_first_de() return value The h
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on sbi->total_valid_bl
In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Add NULL check in raspberrypi_clk_re
In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: fix XQE dma address error The d
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Fix null-ptr-deref in mt7996_mm
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: Fix null-ptr-deref in mt7915_mm
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix hang when cma_netevent_callback fails
In the Linux kernel, the following vulnerability has been resolved: net: phy: clear phydev->devlink when the link is de
In the Linux kernel, the following vulnerability has been resolved: net: phy: mscc: Fix memory leak when using one step
In the Linux kernel, the following vulnerability has been resolved: calipso: Don't call calipso functions for AF_INET s
In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: Add NULL check in aspeed_lpc_enable_sn
In the Linux kernel, the following vulnerability has been resolved: watchdog: lenovo_se30_wdt: Fix possible devm_iorema
In the Linux kernel, the following vulnerability has been resolved: backlight: pm8941: Add NULL check in wled_configure
In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus-ec-sensors) check sensor index in read
In the Linux kernel, the following vulnerability has been resolved: dm: limit swapping tables for devices with zone wri
In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: Add NULL check in udma_probe() devm
In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Reorder clock handling and powe
In the Linux kernel, the following vulnerability has been resolved: serial: Fix potential null-ptr-deref in mlb_usio_pr
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started