Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 325/1777
6.4
CVE-2025-71276

SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.

5.3
CVE-2026-4532

A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vuln

5.3
CVE-2026-4531

A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file interna

6.2
CVE-2019-25589

ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local at

6.2
CVE-2019-25588

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local

6.2
CVE-2019-25587

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration paramete

6.2
CVE-2019-25586

Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplyi

6.2
CVE-2019-25585

Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplyi

6.2
CVE-2019-25584

RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local

6.2
CVE-2019-25583

RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash

5.3
CVE-2026-4530

A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/tex

5.0
CVE-2026-2756

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the

6.5
CVE-2019-25582

i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensi

5.5
CVE-2019-25577

SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arb

6.5
CVE-2019-25574

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files an

6.3
CVE-2026-4516

A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file

6.2
CVE-2019-25572

NordVPN 6.19.6 contains a denial of service vulnerability that allows local attackers to crash the application by submit

6.2
CVE-2019-25571

MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by op

5.5
CVE-2019-25570

RealTerm Serial Terminal 2.0.0.70 contains a denial of service vulnerability that allows local attackers to crash the ap

6.2
CVE-2019-25569

RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allow

6.2
CVE-2019-25567

Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that al

6.2
CVE-2019-25566

TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the

6.2
CVE-2019-25565

Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability in the Serial Code registration field that allows

5.5
CVE-2019-25564

PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by

6.2
CVE-2019-25563

PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by

5.5
CVE-2019-25562

jetAudio 8.1.7 contains a buffer overflow vulnerability in the video converter component that allows local attackers to

6.2
CVE-2019-25561

Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by sup

5.5
CVE-2019-25559

SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local atta

6.2
CVE-2019-25558

Selfie Studio 2.17 contains a denial of service vulnerability in the Resize Image function that allows local attackers t

6.2
CVE-2019-25557

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the applic

6.2
CVE-2019-25556

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local

6.2
CVE-2019-25555

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows lo

5.5
CVE-2019-25554

Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the applica

6.2
CVE-2019-25553

CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the applicatio

6.2
CVE-2019-25551

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supply

6.2
CVE-2019-25550

Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputti

6.2
CVE-2019-25549

VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the applicatio

6.2
CVE-2019-25548

BlueStacks 4.80.0.1060 contains a denial of service vulnerability that allows local attackers to crash the application b

6.2
CVE-2019-25547

NetAware 1.20 contains a buffer overflow vulnerability in the User Blocking feature that allows local attackers to crash

6.2
CVE-2019-25546

NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the

6.2
CVE-2019-25545

Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the applic

6.2
CVE-2019-25544

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providi

6.3
CVE-2026-4515

A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the

6.3
CVE-2026-4514

A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/ad

6.3
CVE-2026-4513

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the fi

6.3
CVE-2026-4511

A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src

4.3
CVE-2026-4510

A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/

6.3
CVE-2026-4509

A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function

4.4
CVE-2026-4161

The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings

4.3
CVE-2026-4143

The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started