Weak server key used for TLS encryption. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Wi
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect
A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as critical. This issue affe
A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from th
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by this issue is the funct
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSy
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods
The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which cou
kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefin
A vulnerability classified as critical has been found in PHPGurukul Notice Board System 1.0. This affects an unknown par
The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site S
Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers
Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior
Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device p
Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write o
Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-
Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to
Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac
Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out
Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get
Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take
Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse
Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to
Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive infor
A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. Thi
A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical
A vulnerability, which was classified as critical, was found in PHPGurukul Teacher Subject Allocation Management System
The Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress plugin for WordPress is vulnerable to Sto
The Employee Directory – Staff Listing & Team Directory Plugin for WordPress plugin for WordPress is vulnerable to Store
A vulnerability, which was classified as critical, has been found in PHPGurukul Rail Pass Management System 1.0. Affecte
A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknow
A vulnerability classified as critical was found in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affe
A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b8
A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as p
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-
A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the
A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulne
Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.
A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_st
A vulnerability, which was classified as critical, has been found in TOTOLINK X2000R 1.0.0-B20230726.1108. Affected by t
webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version
webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version
A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affec
A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknow
A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could all
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows we
A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability af
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started