Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
6.8
Medium
Max CVSS
6.8
Highest
Min CVSS
6.8
Lowest

Browse by Severity

Medium Severity CVEs

Page 101 of 5362
CVSS:6.8(Medium)

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the filename, a user may intentionally use a la...

CVSS:6.8(Medium)

Under certain circumstances unnecessary user details are provided within system logs

CVSS:6.8(Medium)

Under certain circumstances the Linux users credentials may be recovered by an authenticated user.

CVSS:6.8(Medium)

A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit parameter under...

CWE-792024
CVSS:6.8(Medium)

TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.

CWE-792024
CVSS:6.8(Medium)

Improper access control for some Intel(R) Arc(TM) Pro Graphics for Windows drivers before version 31.0.101.5319 may allow an authenticated user to potentially enable escalation of privilege via adjace...

CVSS:6.8(Medium)

An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in an Out-of-Bounds Write.

CVSS:6.8(Medium)

A key used in logging.json does not follow the least privilege principle by default and is exposed to local users in the Rapid7 Platform. This allows an attacker with local access to a machine with th...

CVSS:6.8(Medium)

Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.

CVSS:6.8(Medium)

A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in the subprocess.Po...

CWE-942024
CVSS:6.8(Medium)

A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.

CVSS:6.8(Medium)

JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. The impacted code is the setSigningKey() method within the DefaultJwtP...

CVSS:6.8(Medium)

Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via ...

CWE-792024
CVSS:6.8(Medium)

Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information v...

CWE-792024
CVSS:6.8(Medium)

An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory reset procedure.

CVSS:6.8(Medium)

Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended o...

CVSS:6.8(Medium)

Windows Container Manager Service Elevation of Privilege Vulnerability

CWE-592024
CVSS:6.8(Medium)

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVSS:6.8(Medium)

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVSS:6.8(Medium)

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVSS:6.8(Medium)

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVSS:6.8(Medium)

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVSS:6.8(Medium)

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CWE-202024
CVSS:6.8(Medium)

Windows Mobile Broadband Driver Remote Code Execution Vulnerability