Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may a
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln
An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several
Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this
A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the functio
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The ma
Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect
The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unk
The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and inclu
A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the f
In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure wi
A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload.
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticat
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 coul
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 un
Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of th
MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-
Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE all
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.
Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, m
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo
Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms mo
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request For
A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. Th
Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced
An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to exe
foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.
In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10,
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could
October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authen
The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1
A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business
A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management
A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authentica
An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows
Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even i
ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafte
SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin
The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs be
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerabi
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown f
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown proc
A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unkn
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started