The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl
The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before o
The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the mid
The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private po
Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). T
Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has th
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This i
Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory tr
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site
An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An a
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data
Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_reques
Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that
A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the f
A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function f
Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installati
Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while execut
The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the compon
A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part
A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is
Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on
A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attack
Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The
pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Mult
Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service
Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated u
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or S
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the applicati
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exp
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a de
A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of
A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers
A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certt
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started