The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Sit
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Sho
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'na
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'st
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zi
The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor
The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML A
The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress
The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur
The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download
The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clien
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of i
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confiden
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of i
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t
The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrat
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emit
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce va
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it in
The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cros
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parame
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_
pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticat
A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build
Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a partici
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElem
Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thr
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, un
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started