The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary
NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and man
A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown fu
A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file
IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further a
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.
PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parame
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in
PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CWE-20 Improper Input Validation
Multiple CWE-352 Cross-Site Request Forgery (CSRF)
Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in betw
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.
PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attacker
A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, ma
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword par
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastna
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows re
A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is
A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /i
A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown functio
A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function
A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function
A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not prope
Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2
A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043
A weakness has been identified in Campcodes School Fees Payment Management System 1.0. Affected by this issue is some un
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerabili
A vulnerability was found in Campcodes School Fees Payment Management System 1.0. This affects an unknown function of th
A vulnerability has been found in Campcodes School Fees Payment Management System 1.0. The impacted element is an unknow
A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/
A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown
EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote a
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started