The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data
The AMP Enhancer – Compatibility Layer for Official AMP Plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t
The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'c
The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' para
The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in a
The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all
The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,
The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec
The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versi
The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includi
Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim'
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a P
BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communicat
An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could all
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 all
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attacker
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is in
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted H
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creati
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure o
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attac
Product Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the applica
RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allow
Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to
E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard with
Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enu
FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. ne
grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because
lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is
A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0
Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in t
LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadat
mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vul
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memo
webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of s
webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive
An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server d
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started