The Invoct – PDF Invoices & Billing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data du
The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ
The Category Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag-image' parameter in al
The WPlyr Media Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_wplyr_accent_color' pa
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not neces
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not nec
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is require
Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikY
The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthentic
The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that r
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comme
The Orbisius Random Name Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_label'
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site
The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability
The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all ve
User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbit
JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the
DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fe
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5,
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy
The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PC
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrap
Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.
Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may al
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo
An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read
DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory ex
DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead
Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents
Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o
FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through
Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious sig
Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, whe
The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose informatio
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an autho
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service loc
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an a
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to e
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a netwo
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to appl
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead t
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead t
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started