A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPad
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoi
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPa
The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to bre
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Vent
An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, m
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadO
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3,
An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard
Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.
Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.
An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c a
SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and ch
An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequ
An authenticated user without user-management permissions could identify other user accounts.
An administrator could discover another account's credentials.
An authenticated user without user-management permissions could view other users account information.
An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.
Users who were required to change their password could still access system information before changing their password
A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS
An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arb
Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted sc
Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code
Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr
Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a
Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implem
The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to a
The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs,
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executi
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerabili
A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerabi
A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the
A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown
A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\ad
A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the f
A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classifie
A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Mana
A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected b
A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. It has been declared as problematic. Aff
A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been classified as problematic. Af
A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a mani
Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.
A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started