Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 507/1777
5.5
CVE-2025-43397

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.2, macOS So

5.5
CVE-2025-43396

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macO

5.5
CVE-2025-43394

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1

4.3
CVE-2025-43392

The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7

5.5
CVE-2025-43391

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 26.1 and iPadOS 26.1

5.5
CVE-2025-43390

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issu

5.5
CVE-2025-43389

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS

4.3
CVE-2025-43385

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS

4.3
CVE-2025-43384

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS

4.3
CVE-2025-43383

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS

5.5
CVE-2025-43382

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m

5.5
CVE-2025-43380

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.2,

5.5
CVE-2025-43379

This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Se

5.5
CVE-2025-43378

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe

5.5
CVE-2025-43377

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2,

5.5
CVE-2025-43360

The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentio

5.5
CVE-2025-43348

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,

5.5
CVE-2025-43345

A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPad

4.4
CVE-2025-43336

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonom

5.5
CVE-2025-43335

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, ma

5.5
CVE-2025-43334

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1

5.5
CVE-2025-43322

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macO

5.5
CVE-2025-43288

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26

6.5
CVE-2025-46556

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently

6.5
CVE-2025-35021

By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restrict

6.4
CVE-2025-36172

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0

5.5
CVE-2025-11193

A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application

6.5
CVE-2024-13998

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (includ

5.4
CVE-2021-47698

Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core U

6.5
CVE-2025-63293

FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user

5.0
CVE-2025-12657

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them i

6.1
CVE-2025-63593

Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).

5.4
CVE-2025-8558

Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo

5.4
CVE-2025-50363

Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name

5.4
CVE-2025-63450

Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.

5.4
CVE-2025-63449

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.

6.1
CVE-2025-63448

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.

6.1
CVE-2025-63447

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.

6.1
CVE-2025-63446

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.

4.8
CVE-2025-36093

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content

6.5
CVE-2025-36092

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of

4.3
CVE-2025-36091

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards t

5.4
CVE-2025-63443

School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.

4.6
CVE-2025-63442

Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. T

6.8
CVE-2025-60892

An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-

6.5
CVE-2025-45663

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

6.5
CVE-2025-29699

NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

6.5
CVE-2024-51317

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

5.3
CVE-2025-64294

Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Co

4.3
CVE-2025-12626

A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started