An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_g
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file strea
A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre
The The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug
The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. Thi
A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Obj
AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers
AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote atta
An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script w
An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are n
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when cli
Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages),
Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker w
SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripti
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these op
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gainin
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative
SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, res
Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator wit
A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a car
Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could in
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficientl
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authen
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker c
Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure
Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make
go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discov
Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in
unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-agains
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.
Tanium addressed a local privilege escalation vulnerability in Tanium Server.
Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessi
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security v
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through
Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started