Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 480/1777
6.2
CVE-2025-58305

Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m

4.9
CVE-2025-58304

Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma

4.3
CVE-2025-13737

The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u

4.4
CVE-2025-64315

Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability

5.3
CVE-2025-64313

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may a

5.1
CVE-2025-64311

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect

5.5
CVE-2025-58315

Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect s

6.6
CVE-2025-58314

Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulner

5.1
CVE-2025-58312

Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affec

6.8
CVE-2025-58309

Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability w

6.4
CVE-2025-58307

UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af

6.2
CVE-2025-58294

Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect s

6.5
CVE-2025-66361

An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended p

4.3
CVE-2025-12559

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team em

4.3
CVE-2025-13765

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects De

4.3
CVE-2025-12971

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul

4.3
CVE-2025-59454

In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResour

4.7
CVE-2025-59302

In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following

6.1
CVE-2025-54057

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This

6.1
CVE-2025-13742

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used

4.3
CVE-2025-10476

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability

5.4
CVE-2025-59026

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend

6.1
CVE-2025-59025

Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the us

5.4
CVE-2025-30190

Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can

5.4
CVE-2025-30186

Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend

5.3
CVE-2025-13381

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t

6.5
CVE-2025-13378

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge

5.3
CVE-2025-12584

The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc

5.3
CVE-2025-13441

The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio

5.3
CVE-2025-13157

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions

6.1
CVE-2025-13525

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter i

4.3
CVE-2025-13143

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery i

4.4
CVE-2025-12185

The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to

6.1
CVE-2025-12123

The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via

5.5
CVE-2025-3784

Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose creden

6.4
CVE-2025-12151

The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in

6.4
CVE-2025-12713

The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v

6.4
CVE-2025-12712

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up

6.4
CVE-2025-12670

The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic

6.4
CVE-2025-12666

The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin

6.4
CVE-2025-12649

The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt

5.3
CVE-2025-12579

The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c

4.3
CVE-2025-12578

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including

5.3
CVE-2025-66030

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overfl

6.5
CVE-2025-7449

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18

4.3
CVE-2025-6195

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6

4.3
CVE-2025-65670

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpo

6.5
CVE-2025-12653

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 1

5.4
CVE-2025-65676

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi

5.4
CVE-2025-65675

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started