A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impact
A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issu
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc
In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servi
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of ser
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic
In display, there is a possible information disclosure due to an integer overflow. This could lead to local information
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local informati
In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation
In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local informati
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adj
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servic
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf
In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local e
In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of
In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalatio
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalat
In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatio
A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Re
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also aff
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled.
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started