All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predef
SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to re
SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attacker
P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform admi
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Executi
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injec
The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of
The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a m
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is
The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C
The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers
The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,
The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versi
The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of d
The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's
The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in a
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' paramet
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sen
The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel
In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privile
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of priv
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started