A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remot
The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_ac
The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3.
The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1
The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vu
The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc
The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcod
The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmical
The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attri
The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (a
The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat'
The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver
The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attri
Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may a
Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect i
Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect s
Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerabil
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provid
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab
IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible
In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati
A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c.
The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f
The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{
The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i
The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parame
A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf
A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file
The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver
SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai
SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by
The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c
SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. T
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticate
SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be
SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain,
Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started