Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr
A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file sr
A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file do
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown funct
A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to cra
Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint
Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se
Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that a
Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica
APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace
Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip
Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker
A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that all
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy conf
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration tha
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade
DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing cont
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass
DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function
In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in int
DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a diffe
DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden t
DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS an
DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled n
DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RE
DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPuri
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.
SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExpor
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started