Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 477/1777
4.1
CVE-2025-13001

The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, a

6.5
CVE-2025-13606

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery

5.3
CVE-2025-20792

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

6.5
CVE-2025-20791

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,

5.3
CVE-2025-20790

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

4.4
CVE-2025-20789

In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local informat

4.4
CVE-2025-20788

In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of

6.7
CVE-2025-20777

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2025-20776

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of

6.7
CVE-2025-20775

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20774

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2025-20773

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20772

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20771

In display, there is a possible escalation of privilege due to improper input validation. This could lead to local escal

6.7
CVE-2025-20770

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20769

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

4.7
CVE-2025-20765

In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a

6.5
CVE-2025-20759

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv

4.9
CVE-2025-20758

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if

6.5
CVE-2025-20757

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

6.5
CVE-2025-20756

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE ha

5.3
CVE-2025-20755

In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of se

5.3
CVE-2025-20754

In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service

5.3
CVE-2025-20753

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if

6.5
CVE-2025-20752

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i

6.5
CVE-2025-20751

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i

6.5
CVE-2025-20750

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

6.4
CVE-2025-13697

The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin

4.5
CVE-2025-58488

Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote atta

4.0
CVE-2025-58487

Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity

4.0
CVE-2025-58486

Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary scrip

5.5
CVE-2025-58485

Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary scri

4.0
CVE-2025-58484

Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access parti

5.9
CVE-2025-58483

Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows loc

4.3
CVE-2025-58480

Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access o

4.3
CVE-2025-58479

Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bo

4.3
CVE-2025-58478

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-b

4.3
CVE-2025-58477

Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers

4.2
CVE-2025-58476

Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-o

5.6
CVE-2025-58475

Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write ou

5.4
CVE-2025-55129

HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulner

6.2
CVE-2025-21080

Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local att

5.7
CVE-2025-21072

Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged

5.4
CVE-2025-66415

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafti

5.4
CVE-2025-66412

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

4.6
CVE-2025-66403

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3,

5.3
CVE-2025-66400

mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classna

5.4
CVE-2025-66312

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create

5.4
CVE-2025-66311

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create

5.4
CVE-2025-66310

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started