The Euro FxRef Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cur
A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. This i
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user proc
The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the dat
A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this v
A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is a
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part o
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do
A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This i
A vulnerability was found in PHPGurukul Car Rental Portal 3.0. It has been declared as problematic. This vulnerability a
A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critic
A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability
A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is th
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the functi
A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.pat
A vulnerability classified as critical has been found in Brilliance Golden Link Secondary System up to 20250609. This af
A vulnerability was found in Brilliance Golden Link Secondary System up to 20250609. It has been rated as critical. Affe
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be
A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is the fu
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in
A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5
A vulnerability classified as problematic has been found in Luna Imaging up to 7.5.5.6. Affected is an unknown function
Hydra is a layer-two scalability solution for Cardano. Prior to version 0.22.0, the process assumes L1 event finality an
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated a
Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution
A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality
# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api
The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in a
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modifi
The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u
The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashbo
The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is
OpenList Frontend is a UI component for OpenList. Prior to version 4.0.0-rc.4, a vulnerability exists in the file previe
urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does no
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all r
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the J
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the l
The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the
The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, foote
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OT
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javasc
A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to c
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulne
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allo
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera
Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started