Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 752/1777
6.5
CVE-2024-41795

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de

4.3
CVE-2025-31333

SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modifie

6.6
CVE-2025-31332

Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access

4.3
CVE-2025-31331

SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would

4.4
CVE-2025-30017

Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documenta

4.1
CVE-2025-30015

Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an au

6.7
CVE-2025-30013

SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modul

5.3
CVE-2025-2882

The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between

4.3
CVE-2025-27437

A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server AB

4.2
CVE-2025-27435

Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in t

5.3
CVE-2025-26657

SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could ex

6.8
CVE-2025-26654

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a re

4.7
CVE-2025-26653

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site

4.9
CVE-2025-3430

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up

4.9
CVE-2025-3429

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions u

4.9
CVE-2025-3428

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up

4.9
CVE-2025-3427

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up

4.9
CVE-2019-25223

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in

6.3
CVE-2025-3413

A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified

6.3
CVE-2025-3412

A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown funct

4.3
CVE-2025-0361

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Dev

4.3
CVE-2024-47261

51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have su

6.3
CVE-2025-3411

A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some

6.3
CVE-2025-3410

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code

6.3
CVE-2025-3409

A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_inclu

5.1
CVE-2025-20951

Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows loc

4.0
CVE-2025-20950

Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to

5.5
CVE-2025-20948

Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged

5.5
CVE-2025-20947

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo

4.0
CVE-2025-20945

Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive infor

6.2
CVE-2025-20944

Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read

6.4
CVE-2025-20943

Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory

4.4
CVE-2025-20942

Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local at

6.2
CVE-2025-20941

Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of speci

4.0
CVE-2025-20940

Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 al

5.4
CVE-2025-20939

Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical att

5.5
CVE-2025-20938

Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected da

5.5
CVE-2025-20935

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo

5.5
CVE-2025-20934

Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files w

5.3
CVE-2024-13820

The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi

6.3
CVE-2025-3408

A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the fu

6.3
CVE-2025-3407

A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerabilit

4.3
CVE-2025-3406

A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function

4.3
CVE-2025-3405

A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by

6.3
CVE-2025-3402

A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform 5.5.2 and classified as critic

6.7
CVE-2025-3364

The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to

5.6
CVE-2025-32414

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindi

6.4
CVE-2025-32413

Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.

6.3
CVE-2025-3398

A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the funct

4.3
CVE-2025-3397

A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file mess

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started