HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters
HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack pla
A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This a
HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypas
A vulnerability was found in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file
A vulnerability has been found in code-projects Simple Food Ordering System 1.0. This impacts an unknown function of the
A weakness has been identified in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the fil
A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown proce
A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_m
A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The
A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /
A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of t
A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown func
A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of t
The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5
The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and
The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versio
The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1
The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an
The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on th
The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 throug
The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode
Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect
Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe
A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function o
The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t
The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t
The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortco
The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and
The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi
The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p
Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availabili
Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may aff
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av
A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f
The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver
The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in
The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulner
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modifie
The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to S
The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderb
The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up
A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin
A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edi
A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknow
Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service c
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started