OpenEMR is a free and open source electronic health records and medical practice management application. A logging overs
PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili
A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medi
Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter
A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affect
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medi
PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
A vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected d
An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently dele
A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Uplo
A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown co
Missing Authorization vulnerability in dastan800 Visual Header visual-header allows Exploiting Incorrectly Configured Ac
Missing Authorization vulnerability in Leadinfo Leadinfo leadinfo allows Exploiting Incorrectly Configured Access Contro
Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affec
Missing Authorization vulnerability in UX Design Experts Experto CTA Widget – Call To Action, Sticky CTA, Floating Butto
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CR
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press likec
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT R
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Cr
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay
An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and
Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials becom
The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data
The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If expl
An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to
The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registrat
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for
openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.
Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation b
Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the netwo
A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due
An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows
A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7
Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator
Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects
Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat
Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue a
SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affect
Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration too
Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue a
Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator cre
Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat
Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become com
DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20
wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an
File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue aff
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started