SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated us
Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic use
SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, re
SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could
A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipul
A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files o
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w
WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me
A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipul
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collec
A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the f
LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discove
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi
A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the fil
A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app
A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSO
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge
A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't p
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function i
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue
A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknow
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file
A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects u
A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /a
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some un
A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/p
A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Ap
A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /mat
A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /c
A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/.
In the Linux kernel, the following vulnerability has been resolved: Revert "fs/ntfs3: Replace inode_trylock with inode_
In the Linux kernel, the following vulnerability has been resolved: team: replace team lock with rtnl lock syszbot rep
In the Linux kernel, the following vulnerability has been resolved: f2fs: vm_unmap_ram() may be called from an invalid
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix dereferencing uninitialized error
A vulnerability was detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function o
IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and
A security vulnerability has been detected in itsourcecode POS Point of Sale System 1.0. The affected element is an unkn
A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown proces
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_
An out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting
A NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentiall
Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to sen
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started