The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and
The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a miss
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input
A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an
A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an u
A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issu
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A stored cross-site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this
A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impac
MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the fwhosts.cgi script t
IPFire 2.21 Core Update 127 contains multiple stored cross-site scripting vulnerabilities in the extrahd.cgi script that
IPFire 2.21 Core Update 127 contains multiple cross-site scripting vulnerabilities in the ovpnmain.cgi script that allow
IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script tha
IPFire 2.21 Core Update 127 contains a reflected cross-site scripting vulnerability in the updatexlrator.cgi script that
Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a cross-site scripting vulnerability in the ad
ipPulse 1.92 contains a denial of service vulnerability that allows local attackers to crash the application by providin
A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impact
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge th
A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unau
A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmentation fault, in the `
An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-b
A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length li
A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a
An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return pr
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTem
A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the fu
A security vulnerability has been detected in Alixhan xh-admin-backend up to 1.7.0. This issue affects some unknown proc
Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory` generates an
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor
The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version
A vulnerability was found in newbee-ltd newbee-mall up to a069069b07027613bf0e7f571736be86f431faee. Affected is an unkno
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 1
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SH
In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 1
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SH
The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started