The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics
The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur
The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it
The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r
The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica
The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie
Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR
Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth m
The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o
Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could r
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in COR
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid in
A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the f
A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of t
Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11
A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_comman
Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of servic
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read whe
Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumptio
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumpti
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypa
Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the langua
TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,
Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the Redis
In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datado
In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts a
In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive con
In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission gu
In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWid
In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with
A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functiona
A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCo
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference name
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the c
A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WT
The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex
A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started