In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf
In Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local d
A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the funct
A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B
SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directori
SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable
Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privi
Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malic
Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symme
Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled f
Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exp
A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high
SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a mali
SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script
SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could gra
SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafte
SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user c
Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privi
SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than inte
SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attac
A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unk
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affe
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnera
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affec
Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the gara
Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certa
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vul
In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.10
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-priv
In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103
IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to ob
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bb
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the in
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This a
giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauth
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started