IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authent
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error
On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection confi
IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerabilit
On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly
Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address s
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap c
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a s
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform U
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker wh
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the fee
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the len
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128
In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after ca
There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local inform
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_s
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions V
Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerab
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leak
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user in
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into
Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin lea
A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the funct
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows
Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS
A vulnerability, which was classified as critical, has been found in PHPGurukul Student Study Center Management System 1
Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fes
The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modifi
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored
In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.
SIGB PMB before 8.0.1.2 allows SQL injection.
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attrib
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.
A vulnerability classified as critical was found in Pixelimity 1.0. Affected by this vulnerability is an unknown functio
For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows e
The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone t
In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change()
A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability
Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to pr
Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) al
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started