An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor wit
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was a
IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery
The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for Wo
The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr
The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all
The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet
The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' pa
The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,
The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit
The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil
The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in
The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc
The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid
The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scr
The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.ph
Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attac
Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter i
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab
Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1
The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with
A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from
An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return s
An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi
Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.
Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via
A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in
NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause a
NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer deref
NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer d
Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local
gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.ph
A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers
Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute ar
FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.
FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.
Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue af
Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take
Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near t
CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding addi
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started