Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 711/1777
6.5
CVE-2025-40556

A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet AT

4.7
CVE-2025-40555

A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sendin

4.2
CVE-2025-31929

A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions), IEC 1Ph 7.4kW Chi

6.5
CVE-2025-24510

A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle spec

5.9
CVE-2025-24009

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2

6.5
CVE-2025-24008

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2

5.3
CVE-2024-51447

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login

6.5
CVE-2024-51446

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file

6.5
CVE-2024-51445

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affec

6.5
CVE-2024-51444

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The appli

4.3
CVE-2025-4339

The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t

6.5
CVE-2025-3107

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versio

6.3
CVE-2025-43009

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a

5.8
CVE-2025-43008

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclos

6.3
CVE-2025-43007

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a

6.1
CVE-2025-43006

SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute ma

4.3
CVE-2025-43005

SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT appl

5.3
CVE-2025-43004

Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enabl

6.4
CVE-2025-43003

SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access an

4.3
CVE-2025-43002

SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing aut

6.6
CVE-2025-42997

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the s

6.2
CVE-2025-31329

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions

5.3
CVE-2025-30011

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th

6.1
CVE-2025-30010

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th

6.1
CVE-2025-30009

he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the

4.4
CVE-2025-26662

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject

5.4
CVE-2025-46825

Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a St

5.5
CVE-2025-31260

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be

6.5
CVE-2025-31258

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able

4.7
CVE-2025-31257

This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, ma

5.5
CVE-2025-31256

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unex

5.5
CVE-2025-31251

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7

5.5
CVE-2025-31250

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5.

5.5
CVE-2025-31245

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequ

5.5
CVE-2025-31242

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.5 and

5.3
CVE-2025-31241

A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad

4.3
CVE-2025-31239

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, i

5.5
CVE-2025-31236

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5.

6.5
CVE-2025-31235

A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 1

6.3
CVE-2025-31233

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7

6.8
CVE-2025-31228

The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An

4.6
CVE-2025-31227

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with phys

5.5
CVE-2025-31226

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS

5.5
CVE-2025-31220

A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macO

6.2
CVE-2025-31218

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able

6.5
CVE-2025-31217

The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iP

6.5
CVE-2025-31215

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.

5.5
CVE-2025-31212

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequo

6.5
CVE-2025-31210

The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web

6.3
CVE-2025-31209

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started