The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in
Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This
The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'
The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcod
The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able t
Huawei PCs have a vulnerability that allows low-privilege users to bypass SDDL permission checks . Successful exploitati
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb
The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least
httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req
The Ayyash Studio — The kick-start kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up
The Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable t
The SH Email Alert plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mid' parameter in all v
The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ para
The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aws_search_te
The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of d
RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that coul
Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This a
NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow
A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery f
Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not h
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-sid
A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value
The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code in
A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allo
A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and auth
A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU applicati
accountsservice no longer drops permissions when writting .pam_environment
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request For
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects t
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the functi
The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remov
The Your Simple SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in al
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this iss
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until exp
The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter
The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Sc
The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started