Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 494/1777
4.3
CVE-2025-12377

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification

5.4
CVE-2025-7704

Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability

5.3
CVE-2025-64384

Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configure

6.5
CVE-2025-64383

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-

4.3
CVE-2025-64382

Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woo

6.5
CVE-2025-64381

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking

6.5
CVE-2025-64380

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster f

4.3
CVE-2025-64379

Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectl

5.3
CVE-2025-64370

Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Sec

6.5
CVE-2025-64369

Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly

6.5
CVE-2025-64292

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PascalBajorat Anal

5.3
CVE-2025-64277

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Cont

6.5
CVE-2025-64276

Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access

6.5
CVE-2025-64275

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking

4.3
CVE-2025-64274

Missing Authorization vulnerability in wpkoithemes WPKoi Templates for Elementor wpkoi-templates-for-elementor allows Ex

4.3
CVE-2025-64271

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Reque

4.3
CVE-2025-64269

Missing Authorization vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Exploit

4.3
CVE-2025-64267

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPSwings WooCommerce Ultimat

4.3
CVE-2025-64265

Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorre

5.9
CVE-2025-64264

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Popup addon f

5.4
CVE-2025-64263

Missing Authorization vulnerability in PluginEver WP Content Pilot wp-content-pilot allows Exploiting Incorrectly Config

6.5
CVE-2025-64262

Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Req

5.4
CVE-2025-64261

Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Explo

5.3
CVE-2025-64259

Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configu

6.4
CVE-2025-8397

The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbut

4.3
CVE-2025-12015

The Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed plugin for

6.4
CVE-2025-11769

The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortc

5.3
CVE-2025-11260

The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, a

6.4
CVE-2025-10295

The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting th

5.3
CVE-2025-12681

The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in a

4.9
CVE-2025-12620

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection

5.3
CVE-2025-12891

The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on

5.3
CVE-2025-12979

The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che

5.3
CVE-2025-12892

The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che

5.3
CVE-2025-12536

The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,

4.3
CVE-2025-12366

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object

6.5
CVE-2025-12089

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient

5.4
CVE-2025-64707

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve

4.3
CVE-2025-64705

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve

4.7
CVE-2025-13076

A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the fil

4.7
CVE-2025-13075

A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /ad

4.4
CVE-2025-64517

sudo-rs is a memory safe implementation of sudo and su written in Rust. With `Defaults targetpw` (or `Defaults rootpw`)

4.0
CVE-2025-64503

cups-filters contains backends, filters, and other software required to get the cups printing service working on operati

4.6
CVE-2025-64482

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Editio

6.5
CVE-2025-64429

DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting w

5.4
CVE-2025-63645

A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application'

6.5
CVE-2025-33119

IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be rea

5.4
CVE-2025-36223

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST hea

6.3
CVE-2025-13061

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /ind

6.6
CVE-2025-8421

An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during i

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started