Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa
Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny servic
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hell
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose inform
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder w
Missing Authorization vulnerability in Shahjada Live Forms liveforms.This issue affects Live Forms: from n/a through <=
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broads
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadLis
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of
Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via ad
Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via ad
Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conducto
A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attac
An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested
A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the
An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana serve
A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an
A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthentica
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a r
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a at
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4
An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, versi
The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized lo
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. An HTML injection issue allows users with access to th
Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource with an Insecure Default v
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification
The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'order' and
The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including
The AAWP Obfuscator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-aawp-web' parameter
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application sear
In the Linux kernel, the following vulnerability has been resolved: devlink: fix xa_alloc_cyclic() error handling In c
In the Linux kernel, the following vulnerability has been resolved: dpll: fix xa_alloc_cyclic() error handling In case
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: Fix the potential deadlock When so
In the Linux kernel, the following vulnerability has been resolved: ARM: dts: bcm2711: Fix xHCI power-domain During s2
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup during bt pages loop Dri
In the Linux kernel, the following vulnerability has been resolved: regulator: dummy: force synchronous probing Someti
In the Linux kernel, the following vulnerability has been resolved: regulator: check that dummy regulator has been prob
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started