Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view
The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret
Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exp
Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Acces
Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrect
Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack a
Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-off
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS le
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Stockie Extra st
Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Secu
Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Acces
Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incor
Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This i
Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code In
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg
Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication a
Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly
Missing Authorization vulnerability in Tyler Moore Super Blank super-blank allows Exploiting Incorrectly Configured Acce
Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Re
Insertion of Sensitive Information Into Sent Data vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikboo
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu
Missing Authorization vulnerability in A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Desig
Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Acces
Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using W
The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri
Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email al
Bio.Entrez in Biopython through 186 allows doctype XXE.
Information disclosure while processing system calls with invalid parameters.
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function o
A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/sitecon
A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /c
Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicio
Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allow
PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to uplo
PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to in
UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files w
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible throug
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible thro
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible throug
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated ad
Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the a
Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject maliciou
USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allow
Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows auth
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started