Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would
Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documenta
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an au
SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modul
The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server AB
Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in t
SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could ex
SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a re
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions u
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up
The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in
A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified
A vulnerability, which was classified as critical, was found in mymagicpower AIAS 20250308. Affected is an unknown funct
During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Dev
51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have su
A vulnerability, which was classified as critical, has been found in mymagicpower AIAS 20250308. This issue affects some
A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code
A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_inclu
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows loc
Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to
Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo
Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive infor
Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local at
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of speci
Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 al
Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical att
Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected da
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files w
The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the fu
A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerabilit
A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function
A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by
A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform 5.5.2 and classified as critic
The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindi
Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.
A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the funct
A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file mess
The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. T
A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 169,588 CVE records rated MEDIUM in our database. Of these, 103 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started