Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
6.5
Medium
Max CVSS
6.5
Highest
Min CVSS
6.5
Lowest

Browse by Severity

Medium Severity CVEs

Page 282 of 5362
CVSS:6.5(Medium)

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS:6.5(Medium)

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS:6.5(Medium)

The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 allows users to manipulate the final payment am...

CVSS:6.5(Medium)

The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator enables users to load Secret from arbitrary namespaces upon deployment of the name...

CVSS:6.5(Medium)

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the backends used by vLLM to support structured output (a.k.a. guided decoding). Ou...

CVSS:6.5(Medium)

D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

CWE-772025
CVSS:6.5(Medium)

ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.

CWE-892025
CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.

CVSS:6.5(Medium)

An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.

CVSS:6.5(Medium)

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.

CVSS:6.5(Medium)

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.

CVSS:6.5(Medium)

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.

CVSS:6.5(Medium)

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.

CVSS:6.5(Medium)

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.

CVSS:6.5(Medium)

An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.