The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those
A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster
The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authori
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Aff
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. A
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue a
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.
A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this v
A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is a
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formS
The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo
The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to
Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr
Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V
A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vuln
A vulnerability, which was classified as critical, was found in PHPGurukul Employee Record Management System 1.3. This a
WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerabilit
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t
An out-of-bounds read vulnerability has been reported to affect File Station 5. If a local attacker gains an administra
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vu
A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability c
A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have
A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. A
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by
A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affecte
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an e
A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability a
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mhallmann SEPA Gir
Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa interactive-map-of-
Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.T
Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map interactive-uk-regional-ma
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris McCoy Bacon
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Si
Missing Authorization vulnerability in WP Map Plugins Interactive Regional Map of Florida interactive-map-of-florida all
Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master wp-security-master allows Cross Site
Cross-Site Request Forgery (CSRF) vulnerability in mariusz88atelierweb Atelier Create CV atelier-create-cv allows Cross
Cross-Site Request Forgery (CSRF) vulnerability in Hasina77 Wp Easy Allopass wordpress-easy-allopass allows Cross Site R
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Vide
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Abbi
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for W
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple
Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allo
Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started