Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 522/1777
6.4
CVE-2025-11809

The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode

6.4
CVE-2025-11807

The Mixlr Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mixlr' shortcode in all v

6.4
CVE-2025-11804

The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of

6.4
CVE-2025-10138

The This-or-That plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'thisorthat' shortco

4.9
CVE-2025-10047

The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for W

4.3
CVE-2025-41720

A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserv

4.4
CVE-2025-12033

The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl

4.3
CVE-2025-10588

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forger

4.3
CVE-2025-10570

The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all

6.5
CVE-2025-5983

The Meta Tag Manager WordPress plugin before 3.3 does not restrict which roles can create http-equiv refresh meta tags.

5.5
CVE-2025-10651

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in

5.3
CVE-2025-10638

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allo

6.5
CVE-2025-22167

This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain

6.0
CVE-2025-62592

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

6.0
CVE-2025-62591

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

4.9
CVE-2025-62478

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The support

4.9
CVE-2025-62477

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The s

4.9
CVE-2025-62476

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The s

4.9
CVE-2025-62475

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported versi

4.9
CVE-2025-62289

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supporte

4.9
CVE-2025-62288

Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (co

6.1
CVE-2025-62287

Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server).

4.3
CVE-2025-61885

Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server).

5.9
CVE-2025-61881

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28,

5.3
CVE-2025-61764

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

6.3
CVE-2025-61762

Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Payables). The suppor

5.4
CVE-2025-61761

Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Orde

6.5
CVE-2025-61759

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

6.5
CVE-2025-61758

Vulnerability in the PeopleSoft Enterprise FIN IT Asset Management product of Oracle PeopleSoft (component: IT Asset Man

6.5
CVE-2025-61754

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions t

6.1
CVE-2025-61753

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions

4.3
CVE-2025-61750

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versi

4.3
CVE-2025-53071

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).

5.5
CVE-2025-53070

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a

4.9
CVE-2025-53069

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions

6.5
CVE-2025-53068

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affec

4.9
CVE-2025-53067

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

5.4
CVE-2025-53065

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S

4.3
CVE-2025-53064

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup

5.4
CVE-2025-53063

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S

4.9
CVE-2025-53062

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

5.5
CVE-2025-53061

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S

6.1
CVE-2025-53060

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte

4.9
CVE-2025-53059

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).

6.1
CVE-2025-53058

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Application Logging Inte

5.9
CVE-2025-53057

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

6.1
CVE-2025-53056

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Object and Environment Tech

6.1
CVE-2025-53055

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S

5.5
CVE-2025-53054

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

5.5
CVE-2025-53053

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started