A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when pars
Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames.
The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in al
The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plu
The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio
The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up
The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up
The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable
The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of d
An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions fro
An issue has been discovered in access controls could allow users to view certain restricted project information even wh
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by th
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity o
Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co.,
The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could
The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_foote
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can
Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role t
IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical erro
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input
A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline fu
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation v
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue a
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap S
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox al
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulner
BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability al
CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability
A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allow
TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING param
PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remo
PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allo
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shorten
A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to
The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modif
The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scrip
A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <L
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization templa
A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a spec
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions
A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Se
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.
Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of cr
SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated us
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started