Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This iss
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before output
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputti
A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as critical. Affect
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to
A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the f
A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required
A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the re
A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. This vulnerabilit
A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the
A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected
A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerabi
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This
A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d
A vulnerability was found in code-projects Police Station Management System 1.0. It has been declared as critical. Affec
A vulnerability was found in code-projects Police Station Management System 1.0. It has been classified as critical. Aff
A vulnerability was found in code-projects Tourism Management System 1.0 and classified as critical. This issue affects
A vulnerability has been found in code-projects Tourism Management System 1.0 and classified as critical. This vulnerabi
A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. This affec
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1
A vulnerability was found in merikbest ecommerce-spring-reactjs up to 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd. It has b
A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as problematic. Affected by this vulnerability
A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown funct
A vulnerability, which was classified as critical, was found in Advaya Softech GEMS ERP Portal 2.1. This affects an unkn
A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affe
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in a
A vulnerability classified as critical was found in TOTOLINK N300RH 6.1c.1390_B20191101. This vulnerability affects the
A vulnerability classified as critical has been found in TOTOLINK N300RH 6.1c.1390_B20191101. This affects the function
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been rated as critical. Affected by this issue
A vulnerability, which was classified as problematic, was found in kanwangzjm Funiture up to 71ca0fb0658b3d839d9e049ac36
LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Sit
The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcod
The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versi
The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme
The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or w
Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate T
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0 and classified as critical. This issue affe
A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. T
A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.
A vulnerability classified as critical has been found in gongfuxiang schoolcms 2.3.1. This affects the function SaveInfo
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered whe
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started