A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix
A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affec
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted H
A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, spe
The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a
The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cro
n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) t
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulner
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequ
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequ
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3
A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affect
A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function
Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an a
Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthent
A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBoo
A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as cri
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remot
A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.
DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in t
DevExpress before 23.1.3 allows AsyncDownloader SSRF.
SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute
Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Tick
Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affe
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Thi
The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulner
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97
A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f16
A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f
A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as cr
Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4.
A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the
A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects th
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protectio
A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB and classified as problematic. Affected by this issue i
A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the fi
The eHRMS from 104 Corporation has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attac
Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoi
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Pa
Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats r
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started