A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7,
A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPad
The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an emai
A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption for
CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a log
Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a dis
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of informatio
Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Conditio
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software cou
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker
A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIP
A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templat
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check result
A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow inform
An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption. Note: Softw
When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with sp
A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which hav
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that
On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthent
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an
On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which d
Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-S
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause th
When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can
A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access file
When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory
When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Ident
A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into altern
Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read i
The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification
The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and c
The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google
The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inclu
The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all ver
The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to
The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to,
The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due t
The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter hand
The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu
The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versio
The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.
The TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started