The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slid
Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile vi
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to impr
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to i
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuratio
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due t
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags functi
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags funct
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings fu
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings f
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData f
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups func
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to imp
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php fil
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the view.html.php files
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DeleteSysLogEntry fu
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest funct
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local use
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbi
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functional
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Syn
Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-
Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Stati
Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des
The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc
The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1
The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut
The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi
Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro
AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re
When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view d
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view u
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct
A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct
The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_a
The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_aj
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started