Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensiti
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers t
Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM relate
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data a
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and d
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any
The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, al
The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter befor
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth s
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modif
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the calle
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the Pa
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o
The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a RES
The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side,
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on seve
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body
The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it o
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading maliciou
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same
A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_ex
A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the
A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_arti
A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function make
A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability
A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the fil
A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSyn
A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.
A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functional
A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/inse
A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the fil
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown functi
A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handl
A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_heade
Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersiz
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunctio
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started