Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed
An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access
The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in t
XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Str
A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability a
SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious
A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this r
Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Req
The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-c
An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and
Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.
Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.
Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.
Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.
Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to vi
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, re
A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts
Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating):
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Thi
In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currentl
In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Add missing NULL ptr check in a
In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all
In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Teardown riscv specific bits after kvm
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Don't take register_mutex with copy_fr
In the Linux kernel, the following vulnerability has been resolved: dlm: prevent NPD when writing a positive value to e
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid panic once fallocation fails for
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Clear affinity hint before calling at
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Clear affinity hint before calling at
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadloop in prepare_compress_ov
In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: don't ignore IO flags If blk-wbt
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid accessing uninitialized curseg
In the Linux kernel, the following vulnerability has been resolved: block: fix adding folio to bio >4GB folio is possi
In the Linux kernel, the following vulnerability has been resolved: ext4: goto right label 'out_mmap_sem' in ext4_setat
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: init wiphy_work before allocating r
In the Linux kernel, the following vulnerability has been resolved: idpf: check error for register_netdev() on init Cu
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid journaling sb update on error if journa
In the Linux kernel, the following vulnerability has been resolved: net: Remove RTNL dance for SIOCBRADDIF and SIOCBRDE
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: unregister xdp rxq info in the reset path
In the Linux kernel, the following vulnerability has been resolved: bonding: check xdp prog when set bond mode Followi
In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer dereference in l3mdev_l3_rcv
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started