Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC R
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncann
An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential D
An authenticated attacker can obtain any plant name by knowing the plant ID.
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
An unauthenticated attacker can obtain a user's plant list by knowing the username.
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte
Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). The support
Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (c
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affecte
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Orders). Supported versions tha
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Uplo
Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Su
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that ar
Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job O
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Uplo
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions
Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions tha
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Attachments). Supported ver
Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6,
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started