Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 491/1777
4.9
CVE-2025-13163

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote a

4.8
CVE-2025-60022

Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerabilit

5.3
CVE-2025-13266

A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the f

6.3
CVE-2025-13265

A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the

6.3
CVE-2025-13264

A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown par

6.3
CVE-2025-13263

A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some u

5.3
CVE-2025-13261

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the fil

6.3
CVE-2025-13260

A vulnerability has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file

6.3
CVE-2025-13259

A flaw has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /manufac

6.3
CVE-2025-13256

A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function

6.3
CVE-2025-13255

A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unk

6.3
CVE-2025-13254

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unkno

6.3
CVE-2025-13253

A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of

6.3
CVE-2025-13251

A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can l

6.3
CVE-2025-13250

A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/tr

6.3
CVE-2025-13249

A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /Off

6.3
CVE-2025-13246

A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impa

4.3
CVE-2025-13244

A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown funct

6.3
CVE-2025-13243

A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /

4.3
CVE-2025-13239

A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. A

6.3
CVE-2025-13238

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functio

6.3
CVE-2025-13236

A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the

6.3
CVE-2025-13234

A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function o

5.3
CVE-2025-13221

A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xm

4.7
CVE-2025-13210

A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown func

6.3
CVE-2025-13209

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file

6.3
CVE-2025-13208

A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The im

5.3
CVE-2025-13200

A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknow

5.3
CVE-2025-13199

A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file sign

4.7
CVE-2025-13198

A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload

4.3
CVE-2025-7000

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 1

5.3
CVE-2025-6171

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 1

4.3
CVE-2025-2615

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and

4.3
CVE-2025-11865

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 b

5.3
CVE-2025-12849

The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.

6.5
CVE-2025-8994

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugi

4.3
CVE-2025-12847

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to

4.3
CVE-2025-12494

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insu

4.3
CVE-2025-12182

The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize

6.9
CVE-2025-8386

The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper w

6.5
CVE-2025-64308

The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Bri

6.5
CVE-2025-64307

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized

5.3
CVE-2023-7328

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user manageme

5.3
CVE-2025-13187

A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/si

5.4
CVE-2025-64084

An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in app

5.5
CVE-2025-63745

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_n

4.3
CVE-2025-63744

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_d

4.7
CVE-2025-13185

A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the fi

6.8
CVE-2025-63701

A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.2078

4.3
CVE-2025-13179

A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started