OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p
Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with
Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromis
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflo
A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetVa
A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewa
A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the fil
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown funct
A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown f
A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk
A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects
A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe
A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulat
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter
A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate
The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b
The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co
The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications,
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme
The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow
A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/e
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated us
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause un
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started