yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at se
HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and cr
HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server
In the Linux kernel, the following vulnerability has been resolved: fs/erofs/fileio: call erofs_onlinefolio_split() aft
In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for modul
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer acc
In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize
APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exp
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insuffi
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ pa
The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all v
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored
Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a st
Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks
Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to Externa
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site S
CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to ver
CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers
SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incor
Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.
In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1,
Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsa
An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x
An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.10
Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unautho
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. T
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vul
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by u
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heap
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses,
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authe
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image f
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. M
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be direct
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. A
IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than
Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT req
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issu
The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u
The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ paramete
A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may all
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through
libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is n
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an I
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started