Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an inse
Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a
A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown
A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP h
A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /dr
Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure w
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi
In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard re
In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-
In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_
In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init()
In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue asse
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to
In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdow
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Replace Mutex with Spinlock for RLCG re
In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on p
In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type
In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff
The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri
The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could all
The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to S
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before
A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings comp
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identificatio
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Thi
A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the fu
An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker t
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticat
An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to dele
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree
Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started