Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Er
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core
Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: fro
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affect
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the functi
An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentia
A vulnerability classified as critical was found in Jinher Network OA C6. Affected by this vulnerability is an unknown f
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring un
A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/pop
A vulnerability was found in Novastar CX40 up to 2.44.0. It has been rated as critical. This issue affects the function
Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash colli
A vulnerability, which was classified as critical, was found in ESAFENET CDG 3. Affected is an unknown function of the f
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor
Xorcom CompletePBX is vulnerable to a reflected cross-site scripting (XSS) in the administrative control panel. This
Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup an
After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks,
When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlink
A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_ce
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-sit
OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vu
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce
OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF
OpenEMR is a free and open source electronic health records and medical practice management application. The POST parame
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.1
A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The
A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.
A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrati
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the func
A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown fu
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Allred Infus
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LABCAT Processing
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidpaulsson byBr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in carperfer CoverMan
Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace connector-civicrm-mcrestface
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hiroprot Terms Bef
Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload auto-post-after-image-upload allows Ex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gingerplugins Noti
Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reDim GmbH CookieH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flomei Simple-Audi
Missing Authorization vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows Exploiting Incorrectly
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WeblineIndia Welco
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com cal-com a
Missing Authorization vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Exploiting Incorrectly Configu
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started