SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to ob
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 an
A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unk
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Memory corruption while processing camera TPG write request.
Memory corruption while operating the mailbox in Automotive.
A vulnerability was found in PHPGurukul Car Washing Management System 1.0. It has been rated as critical. Affected by th
Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerab
Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerab
Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerab
A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unkno
A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All
A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control
A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions)
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly va
Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to caus
Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory c
Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to caus
Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allo
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to acc
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcast
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Au
Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows second
Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to acc
Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to res
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privilege
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged
In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait
A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerabilit
A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an
The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attrib
SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link wh
An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect de
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsec
An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German C
A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unk
A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue af
The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthor
The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unk
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vu
The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Store
The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' para
In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of serv
In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of serv
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started