The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripti
Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerabilit
The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up t
The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi
Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne
The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu
On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain
Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu
The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i
A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` compo
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracke
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially craf
Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an
Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.
Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.
Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.
MultiJuicer is used to run separate Juice Shop instances on a central kubernetes cluster without the need for local inst
Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.
Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.
Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.
Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.
Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.
Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.
Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.
Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.
Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.
Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.
Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions.
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.
Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.
Subscriber Broken Access Control in Amelia <= 2.2 versions.
Subscriber Broken Access Control in myCred <= 3.0.3 versions.
Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.
Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started