Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 392/1777
6.5
CVE-2025-15343

Tanium addressed an incorrect default permissions vulnerability in Enforce.

4.3
CVE-2025-15342

Tanium addressed an improper access controls vulnerability in Reputation.

6.5
CVE-2025-15341

Tanium addressed an incorrect default permissions vulnerability in Benchmark.

6.5
CVE-2025-15340

Tanium addressed an incorrect default permissions vulnerability in Comply.

6.5
CVE-2025-15339

Tanium addressed an incorrect default permissions vulnerability in Discover.

6.5
CVE-2025-15338

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

6.5
CVE-2025-15337

Tanium addressed an incorrect default permissions vulnerability in Patch.

6.5
CVE-2025-15336

Tanium addressed an incorrect default permissions vulnerability in Performance.

4.3
CVE-2025-15335

Tanium addressed an information disclosure vulnerability in Threat Response.

4.3
CVE-2025-15334

Tanium addressed an information disclosure vulnerability in Threat Response.

4.3
CVE-2025-15333

Tanium addressed an information disclosure vulnerability in Threat Response.

4.9
CVE-2025-15332

Tanium addressed an information disclosure vulnerability in Threat Response.

4.3
CVE-2025-15331

Tanium addressed an uncontrolled resource consumption vulnerability in Connect.

4.9
CVE-2025-15329

Tanium addressed an information disclosure vulnerability in Threat Response.

5.0
CVE-2025-15328

Tanium addressed an improper link resolution before file access vulnerability in Enforce.

4.3
CVE-2025-15327

Tanium addressed an improper access controls vulnerability in Deploy.

4.3
CVE-2025-15326

Tanium addressed an improper access controls vulnerability in Patch.

6.3
CVE-2025-15325

Tanium addressed an improper input validation vulnerability in Discover.

6.6
CVE-2025-15324

Tanium addressed a documentation issue in Engage.

6.6
CVE-2025-15312

Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.

5.3
CVE-2025-58190

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can

5.3
CVE-2025-47911

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which

5.6
CVE-2025-15551

The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is get

6.8
CVE-2026-0715

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provide

6.8
CVE-2026-0714

A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption o

6.1
CVE-2025-70792

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipu

6.1
CVE-2025-70791

Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipu

5.5
CVE-2025-69619

A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i

5.4
CVE-2025-68643

Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account pre

6.1
CVE-2020-37152

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The ap

4.3
CVE-2020-37145

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrativ

5.3
CVE-2020-37144

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized a

5.5
CVE-2020-37140

Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers t

6.1
CVE-2020-37137

PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attacke

6.2
CVE-2020-37132

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allow

6.2
CVE-2020-37131

Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash t

6.2
CVE-2020-37128

ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by l

5.5
CVE-2020-37127

Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause

5.5
CVE-2020-37121

CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriti

5.4
CVE-2026-1927

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data due

6.5
CVE-2025-14150

IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM

5.1
CVE-2025-13491

IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th

4.9
CVE-2026-23797

In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password

4.7
CVE-2026-1517

A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block.

6.1
CVE-2026-1654

The Peter's Date Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S

5.3
CVE-2026-1271

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref

5.3
CVE-2025-14079

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a

6.4
CVE-2026-1319

The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored C

4.3
CVE-2025-13416

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi

4.7
CVE-2026-25198

web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vu

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started