A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de
SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modifie
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would
Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documenta
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an au
SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modul
The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server AB
Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in t
SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could ex
SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a re
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions u
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up
The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in
A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified
A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown funct
During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Dev
51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have su
A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some
A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code
A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_inclu
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows loc
Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to
Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo
Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive infor
Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local at
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of speci
Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 al
Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical att
Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected da
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files w
The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the fu
A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerabilit
A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function
A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by
A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform 5.5.2 and classified as critic
The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindi
Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.
A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the funct
A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file mess
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started