When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo
Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes
An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which
When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic
A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program com
When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff
Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a
Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a
Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated att
Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts
WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenti
WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers
Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via th
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in al
qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysU
qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysD
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a
Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrato
The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c
ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files
Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and the
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify t
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password use
curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following cond
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the s
The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2
csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the tem
The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modifi
The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-slick' attribute
The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere
Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated at
Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to acce
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged act
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensi
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique id
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all v
The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-S
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started