Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 518/1777
4.3
CVE-2025-5605

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor wit

5.9
CVE-2025-5350

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was a

6.3
CVE-2025-36361

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user

6.8
CVE-2025-12136

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery

5.3
CVE-2025-12134

The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for Wo

6.4
CVE-2025-12096

The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr

4.3
CVE-2025-12072

The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all

6.1
CVE-2025-12017

The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet

4.4
CVE-2025-12016

The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' pa

4.3
CVE-2025-12014

The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab

6.1
CVE-2025-11992

The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,

4.3
CVE-2025-11887

The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check

4.3
CVE-2025-11257

The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap

4.3
CVE-2025-11172

The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability

4.3
CVE-2025-10902

The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit

4.3
CVE-2025-10901

The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil

5.4
CVE-2025-10749

The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in

6.5
CVE-2025-10748

The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc

6.3
CVE-2025-10740

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid

6.4
CVE-2025-10701

The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scr

6.8
CVE-2025-9978

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.ph

5.4
CVE-2025-61931

Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attac

6.1
CVE-2025-58070

Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to

5.5
CVE-2025-10874

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2

6.4
CVE-2025-7730

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter i

4.0
CVE-2025-60023

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit

4.0
CVE-2025-59776

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit

6.8
CVE-2025-58456

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab

5.9
CVE-2025-62517

Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1

5.3
CVE-2025-62236

The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with

6.4
CVE-2025-57848

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from

4.3
CVE-2025-54966

An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return s

6.5
CVE-2025-54963

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi

6.1
CVE-2025-62255

Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.

6.1
CVE-2025-60859

Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via

6.1
CVE-2025-60837

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in

4.4
CVE-2025-23345

NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause a

5.0
CVE-2025-23332

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger

5.5
CVE-2025-23330

NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer deref

5.5
CVE-2025-23300

NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer d

5.5
CVE-2025-10937

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local

6.5
CVE-2025-61464

gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.ph

6.1
CVE-2025-61413

A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers

6.1
CVE-2025-57240

Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute ar

6.5
CVE-2025-50951

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

6.5
CVE-2025-50949

FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.

5.5
CVE-2025-12114

Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue af

5.3
CVE-2025-56009

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take

6.1
CVE-2025-56008

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near t

6.5
CVE-2025-56007

CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding addi

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started