The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-fo
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force a
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Sto
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local a
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browse
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across ident
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a
A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in t
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce chec
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in
The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX han
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a
The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks befor
The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an H
The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, all
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX hand
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored cust
The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field befor
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Ta
The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it ad
The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboa
The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal po
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration setting
The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a w
A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlle
A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-contro
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, an
The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field vi
Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cros
Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to p
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attack
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started