The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef
Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing
HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to re
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma
Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attemp
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp
WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 throug
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i
The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor re
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX
The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend
The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us
The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the se
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W
Full details and mitigation steps are currently restricted and will be published at a later date.
A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-t
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy
The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-
The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu
The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed
The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v
The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started