Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 505/1777
5.3
CVE-2025-54331

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer

5.3
CVE-2025-54330

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read

6.5
CVE-2025-63294

WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create

4.4
CVE-2025-12184

The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up

5.9
CVE-2025-12695

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build

6.4
CVE-2025-12045

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne

6.7
CVE-2025-20749

In charger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2025-20748

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

6.7
CVE-2025-20747

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esca

6.7
CVE-2025-20746

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esca

4.2
CVE-2025-20745

In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege

4.2
CVE-2025-20744

In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privil

4.2
CVE-2025-20743

In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri

6.7
CVE-2025-20741

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

4.7
CVE-2025-20740

In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information

6.7
CVE-2025-20739

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

6.7
CVE-2025-20738

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

6.7
CVE-2025-20736

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

5.3
CVE-2025-20734

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

5.3
CVE-2025-20732

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

5.3
CVE-2025-20731

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

6.7
CVE-2025-20730

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local esc

4.2
CVE-2025-20729

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

6.1
CVE-2025-12456

The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including

6.1
CVE-2025-12452

The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin

6.1
CVE-2025-12416

The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in a

6.1
CVE-2025-12415

The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. T

5.4
CVE-2025-12413

The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to

6.1
CVE-2025-12412

The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc

6.1
CVE-2025-12410

The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu

6.1
CVE-2025-12403

The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and

6.1
CVE-2025-12402

The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin

6.1
CVE-2025-12400

The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin

4.4
CVE-2025-12396

The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t

4.4
CVE-2025-12393

The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions

4.3
CVE-2025-12389

The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi

4.4
CVE-2025-12371

The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versio

6.4
CVE-2025-12369

The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker`

5.3
CVE-2025-12350

The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax

4.3
CVE-2025-12188

The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Si

5.3
CVE-2025-12157

The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca

4.3
CVE-2025-12156

The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to un

4.4
CVE-2025-12065

The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter

6.4
CVE-2025-11812

The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_t

6.5
CVE-2025-11758

The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization

4.4
CVE-2025-11753

The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via

6.5
CVE-2025-47370

Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.

6.1
CVE-2025-47362

Information disclosure while processing message from client with invalid payload.

6.1
CVE-2025-27064

Information disclosure while registering commands from clients with diag through diagHal.

6.1
CVE-2025-12401

The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started