A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. This issue affec
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version
The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all v
A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unkn
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe
A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unkn
A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affect
The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_ma
Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_2
The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vul
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could
The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' sho
The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc
The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server
Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPl
The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript
A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the
Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attack
XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12,
OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allo
: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue af
A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the funct
Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This
An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue i
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating be
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevat
A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the f
XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the bet
A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerabili
A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the f
A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /h
A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management
A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management
A Cross-Site Scripting (XSS) vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGuruku
A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management S
A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketin
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started