The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. T
A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects
A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown pa
libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly de
A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is n
Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Ad
Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init
Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialRefe
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:
A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML v
EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data po
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowi
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior t
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior t
Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a speci
A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been rated as critical. Affected by this issue is some unk
A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB)
A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace D
A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerabili
Information disclosure may be there when a guest VM is connected.
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verifi
Memory corruption while processing IOCTL calls to add route entry in the HW.
Memory corruption while accessing MSM channel map and mixer functions.
Memory corruption while invoking IOCTL map buffer request from userspace.
There may be information disclosure during memory re-allocation in TZ Secure OS.
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affect
Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service
File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulne
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if
In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri
In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this v
Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this v
Vulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vu
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through i
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started