MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypa
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could m
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-539
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a
jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability whe
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript pa
Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker
Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could upd
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker c
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated att
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete
The Material Master application does not enforce authorization checks for authenticated users when executing reports, re
Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthent
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management (SICF Handler in SRM Catal
The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5
jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() AP
jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin
A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServe
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 a
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sor
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of
A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Em
An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause
A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neu
Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl
A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file pac
A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file po
A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the fi
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML inje
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated S
Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low
Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in a
Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external we
A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions li
A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of t
A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown functio
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started