Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithT
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A
A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch betw
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut
This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data
In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie
A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo
The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T
Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hij
A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the
A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted elem
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callb
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok
Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32
In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper
An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively re
Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `re
Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces
URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data
Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th
Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection s
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; durin
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), v
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concaten
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored
The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-
The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han
The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated tr
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive
Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34).
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started