Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 441/1777
5.3
CVE-2025-68982

Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Inco

5.3
CVE-2025-68981

Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting

5.3
CVE-2025-68980

Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Inco

5.3
CVE-2025-68979

Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-

6.5
CVE-2025-68978

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig

6.5
CVE-2025-68977

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig

5.4
CVE-2025-68976

Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured

4.3
CVE-2025-68975

Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploi

6.6
CVE-2025-68974

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

6.1
CVE-2025-15355

ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticat

5.3
CVE-2025-15229

A vulnerability has been found in Tenda CH22 up to 1.0.0.1. Affected by this vulnerability is the function fromDhcpListC

5.0
CVE-2025-15222

A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readO

6.1
CVE-2025-14313

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outpu

6.1
CVE-2025-14312

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outpu

4.3
CVE-2025-15220

A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. This affects the function init of the file src/main/java/

4.3
CVE-2025-15213

A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown f

6.3
CVE-2025-15212

A vulnerability was detected in code-projects Refugee Food Management System 1.0. This issue affects some unknown proces

6.3
CVE-2025-15211

A flaw has been found in code-projects Refugee Food Management System 1.0. Impacted is an unknown function of the file /

6.5
CVE-2025-68499

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs

6.5
CVE-2025-68498

Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Contr

5.4
CVE-2025-68120

To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.

6.5
CVE-2025-68040

Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allo

6.3
CVE-2025-15210

A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This vulnerability affec

5.4
CVE-2023-41656

Missing Authorization vulnerability in wpdive Better Elementor Addons allows Exploiting Incorrectly Configured Access Co

5.4
CVE-2023-32238

Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): fr

6.3
CVE-2025-15209

A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown part of the

6.5
CVE-2025-68607

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita

6.5
CVE-2025-68504

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear

6.5
CVE-2025-68503

Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Contr

4.3
CVE-2025-68502

Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorr

6.3
CVE-2025-69205

Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and incl

6.3
CVE-2025-15205

A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an

6.5
CVE-2025-69202

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream servi

6.5
CVE-2025-14175

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling

6.5
CVE-2025-68431

libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the

6.3
CVE-2025-15199

A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown f

6.8
CVE-2025-14728

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue clie

5.3
CVE-2025-14280

The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ

4.8
CVE-2025-55064

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

4.8
CVE-2025-55063

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

4.8
CVE-2025-55062

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

6.1
CVE-2025-55060

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

6.5
CVE-2025-68868

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Tex

5.3
CVE-2025-53627

Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces as

4.7
CVE-2025-15197

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vul

4.3
CVE-2025-69206

Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Serv

5.4
CVE-2025-68951

phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vuln

4.9
CVE-2025-68893

Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Si

5.4
CVE-2025-68928

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could s

6.1
CVE-2025-65442

DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrar

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started