The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in
The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter
Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect avail
Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation of this vulnerabili
Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availab
Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerabi
Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this
The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Requ
Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnera
The Art Theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'arttheme_them
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c
Cross-site request forgery vulnerability exists in surveillance cameras provided by i-PRO Co., Ltd.. If a user views a c
The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and in
A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250516. It has been classified as problematic. This affec
IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a speci
IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when
IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes i
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.1
A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424.
A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250
A vulnerability classified as critical was found in Brilliance Golden Link Secondary System up to 20250424. This vulnera
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. This impacts the function subscribe_to_spot/subscribe
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as critic
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Con
The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vec
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as cri
A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0.
The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vect
A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by
Missing Authorization vulnerability in BdThemes Element Pack Pro allows Exploiting Incorrectly Configured Access Control
Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issu
A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This
A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability af
A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers
The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, t
Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user manage
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptograph
Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenti
A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the
A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows auth
A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to th
A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allow
Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated u
A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affecte
A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnera
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unkn
A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affec
A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been declared as critical. This vulnerab
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started