In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Infor
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newslet
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor
The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitl
The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and inc
A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided
RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the wri
Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled
The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio
The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shor
The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,
The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar
The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5
The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_producti
The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter'
The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up t
Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP
A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to acc
A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitr
A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploi
A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote a
A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed c
Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92
A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unkno
Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security
Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stor
In the Linux kernel, the following vulnerability has been resolved: USB: chipidea: fix memory leak with using debugfs_l
In the Linux kernel, the following vulnerability has been resolved: genirq/ipi: Fix NULL pointer deref in irq_data_get_
In the Linux kernel, the following vulnerability has been resolved: caif: fix memory leak in cfctrl_linkup_request() W
In the Linux kernel, the following vulnerability has been resolved: workqueue: fix data race with the pwq->stats[] incr
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Enhance sanity check while generating att
In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Catch overflow of uptr and length
In the Linux kernel, the following vulnerability has been resolved: powerpc: Don't try to copy PPR for task with NULL p
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: Change logging to dev for mtk_dp_
In the Linux kernel, the following vulnerability has been resolved: drm/msm/mdp5: Don't leak some plane state Apparent
In the Linux kernel, the following vulnerability has been resolved: ext2/dax: Fix ext2_setsize when len is page aligned
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle kvm_arm_init failure correctly i
In the Linux kernel, the following vulnerability has been resolved: recordmcount: Fix memory leaks in the uwrite functi
In the Linux kernel, the following vulnerability has been resolved: ext4: fix WARNING in mb_find_extent Syzbot found t
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix wrong setting of max_corr_read_error
In the Linux kernel, the following vulnerability has been resolved: net: fix net_dev_start_xmit trace event vs skb_tran
In the Linux kernel, the following vulnerability has been resolved: power: supply: axp288_fuel_gauge: Fix external_powe
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Fix integer overflow in radeon_cs_parse
In the Linux kernel, the following vulnerability has been resolved: fsdax: force clear dirty mark if CoW XFS allows Co
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration w
In the Linux kernel, the following vulnerability has been resolved: net: hns: fix possible memory leak in hnae_ae_regis
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_create() If the cifs al
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started