An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response
An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff
Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Su
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbit
pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track chang
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacke
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker wi
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute a
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use s
A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validat
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an
E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0,
OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the or
In JotUrl 2.0, is possible to bypass security requirements during the password change process.
In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insec
SQL injection vulnerability found in Enricozab CMS v.1.0 allows a remote attacker to execute arbitrary code via /hdo/hdo
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only t
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally.
This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when ex
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into inclu
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerab
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerabili
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab
cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.
A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially lea
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started