A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__b
A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_
WeGIA is Web manager for charitable institutions A Stored Cross-Site Scripting (XSS) vulnerability was identified in the
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Typ
There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica
Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain
The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS).
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7
Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and ear
An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2
IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt
IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio
Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.
The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software p
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass
The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due
The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Displa
The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via
The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability
The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cro
The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch
The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capab
The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th
CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.
A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to exe
An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira D
HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing
Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to
A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated use
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other p
This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff
A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and
A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenti
An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive info
A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fs
User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct
Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary c
Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote att
Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary
Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and
Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Ma
Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started