A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator ac
A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator ac
An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gain
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an admini
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user acc
A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a r
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account
An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accoun
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an admin
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator a
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local netwo
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 th
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an
GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8
GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 1
The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access
The Slideshow Wp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sswpid' attribute of the 'ss
The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch
The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to,
The Flask Micro code-editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's codeflask
The OpenPOS Lite – Point of Sale for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t
The Microtango plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'restkey' parameter of the mt_r
The HTML Tag Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in
The WDES Responsive Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdes-popup
The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started