Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 501/1777
5.3
CVE-2025-2534

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes

6.5
CVE-2025-12890

Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the

6.5
CVE-2024-47118

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNI

6.5
CVE-2025-63718

A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient

6.5
CVE-2025-63716

The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unautho

6.1
CVE-2025-63714

Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute

6.1
CVE-2025-63713

Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary

6.5
CVE-2025-57697

AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image

4.7
CVE-2025-12873

A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /a

6.2
CVE-2025-12829

An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data an

6.1
CVE-2025-63785

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2

6.5
CVE-2025-63784

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback

6.3
CVE-2025-12862

A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknow

6.5
CVE-2025-63687

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/

6.5
CVE-2025-63686

There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c938116

5.4
CVE-2025-58465

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a us

4.9
CVE-2025-58463

A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an admi

6.5
CVE-2025-57712

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

5.4
CVE-2025-57706

A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user

4.8
CVE-2025-54168

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an admin

6.5
CVE-2025-53413

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

6.5
CVE-2025-53412

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

4.9
CVE-2025-53411

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

6.5
CVE-2025-53410

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

6.5
CVE-2025-53409

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

6.5
CVE-2025-53408

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-52865

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-47207

A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gain

4.7
CVE-2025-12861

A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the

4.7
CVE-2025-12860

A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php.

4.7
CVE-2025-12859

A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_

4.7
CVE-2025-12857

A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknow

4.7
CVE-2025-12856

A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /

4.7
CVE-2025-12855

A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processi

4.7
CVE-2025-12853

A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function dele

4.3
CVE-2025-46413

Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. W

4.3
CVE-2025-10966

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host

5.4
CVE-2025-64339

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature i

4.3
CVE-2025-12527

The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capabili

4.0
CVE-2025-12520

The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all

5.4
CVE-2025-64336

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is v

5.5
CVE-2025-64329

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 thro

6.5
CVE-2025-4522

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct

5.3
CVE-2025-64323

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack a

4.4
CVE-2025-64187

OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vul

6.9
CVE-2025-52662

A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extra

6.1
CVE-2025-12789

A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout p

6.4
CVE-2025-64302

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing

6.5
CVE-2025-12636

The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to ba

5.3
CVE-2025-64179

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below,

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started