A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the fi
A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impact
A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the f
A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by thi
A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected
A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-b
A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/Download
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the
A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file
A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_43F020 of the file
A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unkn
A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_
A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/in
A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file
A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publi
A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/public
A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/meth
A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.j
A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.p
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allow
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The en
WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the fil
A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/
A vulnerability was determined in jsbroks COCO Annotator up to 0.11.1. This impacts an unknown function of the file /api
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function
A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element
A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the fu
A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /gofor
A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /gofor
A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the
The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and inclu
The MP-Ukagaka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including
The Subitem AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']
The Wonka Slide plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `list_class` shortcod
The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops
The Video Onclick plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `youtube` shortcode
The OMIGO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `omigo_donate_button` short
The Simple Bible Verse via Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX
The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr
The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the functi
A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vuln
A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the
The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started