A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part
A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by thi
A vulnerability classified as critical was found in godcheese/code-projects Nimrod 0.8. Affected by this vulnerability i
A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected b
A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14
Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certai
The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to
In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarti
In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal
FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a ma
A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerab
In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=n
A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash whe
A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0.
In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared articl
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor a
In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are trigger
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to f
Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograph
WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt
Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt
Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographica
Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. String::Random defaults to Perl's bui
A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type bu
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue
The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay,
The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_opti
The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and i
A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass au
The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v
IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be e
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affect
A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknow
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
Buffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987
A vulnerability classified as problematic has been found in xujiangfei admintwo 1.0. This affects an unknown part of the
A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unkn
A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerabilit
A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown functio
Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Re
Cross-Site Request Forgery (CSRF) vulnerability in wprio Table Block by RioVizual riovizual allows Cross Site Request Fo
Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Exploiting Incorrectly Confi
Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z administrator-z allows Cross Site Request F
Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all-phpbb-integration allows Cross Site Req
Cross-Site Request Forgery (CSRF) vulnerability in freetobook Freetobook Responsive Widget freetobook-responsive-widget
Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist wishlist allows Cross Site Request Forgery.This
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started