Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in t
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac
rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handl
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou
A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrar
A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Manageme
A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management
A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management setting
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c
Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that a
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The cli
An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with
stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verifica
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn
The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7
The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.
The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to St
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio
The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Sto
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all v
The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, an
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' param
The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t
The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c
The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a
The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a
The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and
The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio
The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio
The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflec
The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-S
The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started