In the Linux kernel, the following vulnerability has been resolved: drm/msm: adreno: fix deferencing ifpc_reglist when
In the Linux kernel, the following vulnerability has been resolved: scs: fix a wrong parameter in __scs_magic __scs_ma
Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode
Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo
Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Over
The Short Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'short_link_post_title' and 'sh
The LinkedIn SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'linkedin_sc_date_format', 'li
The Electric Studio Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se
The WMF Mobile Redirector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a
The WP Allowed Hosts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allowed-hosts' parameter
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln
The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error
The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa
The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da
The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i
The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,
The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all
The SearchWiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in search results in all
The Real Post Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a
The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'c
The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The List Site Contributors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alpha' paramete
The Kunze Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcode in all versions u
The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all
The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ
The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a
The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcr
The Internal Link Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve
The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized m
The PDF Resume Parser plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in
The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. Th
The Testimonials Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version
The Makesweat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'makesweat_clubid' setting in al
The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' short
The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users mac
Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner
Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vuln
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect a
Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may af
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner
Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner
A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration
Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject ma
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started