A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability
A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952
A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c673
A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated u
IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticat
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticat
IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext paramete
A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedea
A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is th
A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the functio
A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of t
A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function trans
A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the fun
A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAuto
A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ad
A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects
A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown
A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issu
The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to I
A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critica
A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affec
A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulner
The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_ele
The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Buil
The Product Subtitle for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmlTag’
The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fastspring/block-fast
The Daisycon prijsvergelijkers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'daisy
A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affe
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highl
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions p
An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a
vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, th
vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a
vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, h
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via
vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDo
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker
Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dic
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth c
An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which
A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin service
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace
Perl threads have a working directory race condition where file operations may target unintended paths. If a directory
A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploite
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started