WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectiv
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source AP
A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitr
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic
Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteo
Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in sale
Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy o
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/
MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate
### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing a
MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate reque
MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names c
MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consis
MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissio
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistentl
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status c
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate cer
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cro
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versi
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started