Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Cust
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo
A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe
A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre
OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame
Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe
A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted
A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function sc
A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored C
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up
The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leadin
An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke Ca
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti
A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the fi
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unkn
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packa
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started