gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs w
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_s
filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing at
SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolut
A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting
An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression st
A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process
An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to b
Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentica
An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more tha
An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin i
An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal ha
An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands
An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU dispr
An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an
An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator
An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a c
When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused b
A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when pro
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain
A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote au
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & L
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email c
The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to buil
SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns t
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advan
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowi
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capab
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly saniti
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size' Shortcode Attrib
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaus
A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeli
A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.0. Impacted is the function import_session
A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue affects the function path.resolve of the file src/
A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instruct
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing
The affected Ebyte device web management interface does not restrict the interface from being rendered within an extern
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started