An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled
An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c
An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open
An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t
Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may caus
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM E
A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This af
A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Af
A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vu
Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacke
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker wh
Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass co
Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit hea
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions
Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has be
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorize
Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 a
NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using t
In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) d
In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authen
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected
PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in odms/admin/view-user-q
PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-de
PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/requ
A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vu
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_
A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the f
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in
When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correc
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified
A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol a
A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface
A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from
A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to
An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device
The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter
WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be
Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B
Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-sit
A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the functio
Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scr
Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to
Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to r
Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block ot
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and
A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerabilit
A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affect
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started