An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read
WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create
The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne
In charger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esca
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esca
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege
In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privil
In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local esc
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin
The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in a
The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. T
The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to
The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc
The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu
The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin
The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin
The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t
The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions
The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi
The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versio
The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker`
The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax
The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Si
The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca
The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to un
The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter
The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_t
The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization
The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
Information disclosure while processing message from client with invalid payload.
Information disclosure while registering commands from clients with diag through diagHal.
The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started