Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a
Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a
Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privile
Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V
OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker c
Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request UR
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe tem
A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the N
Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability w
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i
Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerabi
Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability
Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerabil
Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect a
The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect av
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may a
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av
Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerab
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec
Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerabilit
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who
The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and ef
Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisti
Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access
Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons all
Server-Side Request Forgery (SSRF) vulnerability in SkatDesign Ratatouille ratatouille allows Server Side Request Forger
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled
Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affect
Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiti
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Woo
Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Acce
Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S
Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing all
Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Confi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Thea
Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allow
The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to,
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacera
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started