Dell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redi
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3
An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and
An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions start
An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17
An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f
The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publ
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Roundup Recipe Name field
The WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins plugin for WordPress is vulnerable t
The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Di
The CC-IMG-Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'img' shortcode
The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a mi
Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi proven
An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specifi
AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects Ale
An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated
CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP s
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP
Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAl
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisc
A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow
A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv
Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low
CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized use
Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnera
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vuln
XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostna
Flarum is open-source forum software. A session hijacking vulnerability exists in versions prior to 1.8.10 when an attac
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local at
IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) pl
An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows
Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generati
In the Linux kernel, the following vulnerability has been resolved: powerpc/code-patching: Fix KASAN hit by not flaggin
In the Linux kernel, the following vulnerability has been resolved: gtp: Suppress list corruption splat in gtp_net_exit
In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix incorrect initialization order S
In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to L
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: f_midi: f_midi_complete to call queue_
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix error handling causing NULL
In the Linux kernel, the following vulnerability has been resolved: sockmap, vsock: For connectible sockets allow only
In the Linux kernel, the following vulnerability has been resolved: bpf: avoid holding freeze_mutex during mmap operati
In the Linux kernel, the following vulnerability has been resolved: net: Add rx_skb of kfree_skb to raw_tp_null_args[].
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Use spin_lock_irqsave() in interruptib
In the Linux kernel, the following vulnerability has been resolved: nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() A
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started