The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe
The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a
A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_conte
A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the
The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor N
In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a
An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can caus
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the c
RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frame
In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a
Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type,
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of se
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints i
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnera
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally s
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code
Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerabilit
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instan
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthe
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerab
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerabi
Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used i
In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client
In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for
Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as th
Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple M
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels
Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Con
libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexe
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, au
Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endp
Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spri
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started