A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown funct
A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of
A security vulnerability has been detected in happyfish100 libfastcommon up to 1.0.84. Affected by this vulnerability is
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatu
Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may a
Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerabi
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability
Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect ava
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerabi
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec
Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect ser
Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availa
Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availabi
Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect av
Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect
UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.
Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability
Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerability will affect avail
Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect avai
The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' paramete
A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function P
A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of
The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter
A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability
A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/sy
The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in
The Docus – YouTube Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'docusplayl
The Orange Confort+ accessibility toolbar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to,
A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allow
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions
A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. Th
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component
A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the
A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e298
A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component
A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pf
The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is
A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/
A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the
A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Perform
Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Devel
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the
A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the
A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attac
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started