The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Tabl
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin f
Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsi
A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of
A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part
The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is
A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file
A security vulnerability has been detected in yangzongzhuan RuoYi up to 4.8.2. This issue affects some unknown processin
A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the
A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /ad
A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the f
WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialM
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting
WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkE
A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of
A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function
A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generate
AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by su
Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local atta
AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the application b
NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated users
Fast AVI MPEG Joiner 1.2.0812 contains a buffer overflow vulnerability that allows local attackers to crash the applicat
GSearch 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by input
UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows
UltraVNC Viewer 1.2.2.4 contains a denial of service vulnerability that allows attackers to crash the application by sup
Backup Key Recovery 2.2.4 contains a denial of service vulnerability that allows local attackers to crash the applicatio
HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability that allows local attackers to crash the applic
NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attacke
SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to c
jetAudio 8.1.7.20702 Basic contains a denial of service vulnerability that allows local attackers to crash the applicati
ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by su
jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by su
PHPRunner 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supply
DNSS Domain Name Search Software 2.1.8 contains a buffer overflow vulnerability in the registration code input field tha
Axessh 4.2 contains a denial of service vulnerability in the logging configuration that allows local attackers to crash
A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is an unknown function of the file /cgi-bin
A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageControl
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loadi
A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. Impacted is the function action_ipsec_conn of
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-
A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown fu
SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started