justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code s
justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler
justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling.
justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability
justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializ
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function
A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, a
A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/
A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of t
A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of
A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affect
A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affe
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vul
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the f
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerab
The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to
hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. Wh
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an inpu
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compa
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that
The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of da
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form respon
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dela
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install
SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, a
WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in th
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php th
AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that all
AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthentica
The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of th
The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to
The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allow
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway w
The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauth
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8
OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started