Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Co
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform un
WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include a
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that
WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated at
WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers
WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers
WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to pe
WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabili
WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthoriz
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote
The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing
The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marke
The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax f
A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd
A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellBy
A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file
A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function get
A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of
A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0. This affects an unknown function of t
A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown functio
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of th
A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the
A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntit
A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown par
A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of
A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component
A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the fi
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-passwor
The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy s
In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized fo
A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impa
A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of t
The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che
The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizatio
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcod
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script
The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in v
Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at
Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacker
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo
OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started