Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m
Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma
The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u
Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may a
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect s
Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulner
Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affec
Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability w
UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af
Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect s
An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended p
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team em
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects De
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul
In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResour
In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend
Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the us
Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can
Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge
The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc
The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio
The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions
The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter i
The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery i
The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to
The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via
Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose creden
The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in
The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v
The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up
The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic
The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin
The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt
The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c
The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overfl
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18
GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6
An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpo
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 1
Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi
Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started