A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 a
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Forti
Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMan
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete
A vulnerability, which was classified as problematic, was found in Stoque Zeev.it 4.24. This affects an unknown part of
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant S
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant S
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-
An issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used t
The Spreadsheet view is vulnerable to a XSS attack, where a remote unauthorised attacker can read a limited amount of va
An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consum
A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the funct
A vulnerability was found in libzvbi up to 0.2.43. It has been declared as problematic. Affected by this vulnerability i
A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_s
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro
Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi
The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settin
The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the p
The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which c
The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all vers
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro
The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to c
The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of
User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process,
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Sit
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other us
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated use
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint tha
SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorizat
SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to
SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting.
An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing
Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the applicat
SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debuggi
SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence repo
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of servic
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive informa
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) cont
Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.
A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HT
Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality
This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have l
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started