A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet AT
A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sendin
A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions), IEC 1Ph 7.4kW Chi
A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle spec
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affec
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The appli
The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versio
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a
Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclos
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a
SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute ma
SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT appl
Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enabl
SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access an
SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing aut
Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the s
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th
he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the
The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject
Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a St
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able
This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, ma
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unex
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5.
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequ
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.5 and
A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, i
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5.
A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 1
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7
The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with phys
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS
A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macO
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able
The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iP
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequo
The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started