The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in a
The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' par
The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of
The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to
The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up
The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in al
MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'l
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the functi
A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/
A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through
A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.1
The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress
A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /ma
A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct
Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aia
The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fi
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file
A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthro
The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modif
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, v
A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the fil
A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of
eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user perfo
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data F
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil
A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /man
A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functi
Memory Corruption when sending random number generator command with insufficient output buffer size.
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
Memory corruption in windows drivers while sending incorrect trusted application request
Memory corruption in diagnostic services due to absence of input validation
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-spa
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a
In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper in
A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transa
A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the functi
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null c
In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to imprope
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead t
In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustio
In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due
In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started