Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Count
An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices
An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices
An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO d
An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices t
The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capabil
The Xavin's List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls'
The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' s
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights fu
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its public
The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in al
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.
The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Dire
The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation
Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha form
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024
In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the m
Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mod
Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an anal
MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/u
Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot whi
An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Element
Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't bee
A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the
A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown
A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424.
A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250
The Cision Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all version
A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is th
Memory corruption while processing an IOCTL call to set mixer controls.
Memory corruption can occur during context user dumps due to inadequate checks on buffer length.
Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.
Memory corruption while sound model registration for voice activation with audio kernel driver.
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Memory corruption due to improper bounds check while command handling in camera-kernel driver.
Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corres
Memory corruption during concurrent access to server info object due to unprotected critical field.
A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected i
A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critic
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulner
Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerabilit
Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability
Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vul
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will a
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will a
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started