The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order
The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc
The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all
The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan
The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param
The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti
The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port for
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates
A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the
A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the
A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the
A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec o
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provide
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions -
Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values coul
BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati
An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c
An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac
When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal
An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi
An authenticated user with limited read privileges may be able to access documents from collections they are not authori
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf
An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In
Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started