The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up
The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,
The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter
The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to
The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions
The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capa
The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure i
The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check
The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including,
The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This i
The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch
The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ
The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin
The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortc
The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting
The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all
The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attrib
The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode i
The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in
The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortco
The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketw
The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the
The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribu
The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcod
The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_
The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al
The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1
The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'typ
SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the
Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could b
SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting
Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal
Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally a
Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adja
Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL
Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac
SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end
SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information
Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could
Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled functio
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL u
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic
In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature r
SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio
Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2
Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence
ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulne
KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot
Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started