A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data UR
A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffe
Missing Authorization vulnerability in istmoplugins GetBookingsWP get-bookings-wp allows Exploiting Incorrectly Configur
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cheesefather Botne
Missing Authorization vulnerability in gunnarpayday Payday payday allows Exploiting Incorrectly Configured Access Contro
Missing Authorization vulnerability in matthewrubin Local Magic local-magic allows Exploiting Incorrectly Configured Acc
Missing Authorization vulnerability in Frank P. Walentynowicz FPW Category Thumbnails fpw-category-thumbnails allows Exp
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vlad.olaru Fonto fonto a
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pixelgrade Category Icon
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in publitio Publitio publit
Missing Authorization vulnerability in Plugin Devs Shopify to WooCommerce Migration migrate-shopify-to-woocommerce allow
Missing Authorization vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-woocommerce
Missing Authorization vulnerability in Matat Technologies TextMe SMS textme-sms-integration allows Exploiting Incorrectl
Missing Authorization vulnerability in OTWthemes Widget Manager Light widget-manager-light allows Accessing Functionalit
Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View free-product-table-for-woocom
Missing Authorization vulnerability in Think201 Clients clients allows Exploiting Incorrectly Configured Access Control
Missing Authorization vulnerability in Manuel Schmalstieg Minimalistic Event Manager minimalistic-event-manager allows E
Missing Authorization vulnerability in richtexteditor Rich Text Editor richtexteditor allows Exploiting Incorrectly Conf
Missing Authorization vulnerability in jeffikus WooTumblog woo-tumblog allows Exploiting Incorrectly Configured Access C
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Utkarsh Kukreti Ad
Missing Authorization vulnerability in Sandeep Kumar WP Video Playlist wp-video-playlist allows Exploiting Incorrectly C
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Greg TailPress tailpres
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in docxpresso Docxpresso do
Missing Authorization vulnerability in TuriTop TuriTop Booking System turitop-booking-system allows Exploiting Incorrect
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolut
Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all
Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file i
The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an
A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been declared as problematic.
The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix error code in chan_alloc_skb_cb() T
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: Fix NAPI registration
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix memleak of nhc_pcpu_rth_output in fib_che
In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix out of bound read in strscpy() sourc
In the Linux kernel, the following vulnerability has been resolved: netfs: Call `invalidate_cache` only if implemented
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: drop beyond-EOF folios with the rig
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registratio
In the Linux kernel, the following vulnerability has been resolved: xsk: fix an integer overflow in xp_create_and_assig
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix fence reference count leak The last
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge
The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' s
UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attachin
A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affecte
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points t
The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in
A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started