Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 523/1777
6.1
CVE-2025-53052

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp

5.4
CVE-2025-53048

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supp

5.8
CVE-2025-53047

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are

4.9
CVE-2025-53046

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported

4.9
CVE-2025-53045

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2025-53044

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2025-53042

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.1
CVE-2025-53041

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th

4.9
CVE-2025-53040

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-53035

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic

5.4
CVE-2025-53034

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic

6.5
CVE-2025-50075

Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli

4.9
CVE-2025-50074

Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli

6.1
CVE-2025-62249

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025

6.1
CVE-2025-61457

code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php.

6.1
CVE-2025-61255

Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search pa

5.1
CVE-2025-56802

The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files

5.1
CVE-2025-56801

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB

5.1
CVE-2025-56800

Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application impl

6.5
CVE-2025-56799

Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism

6.5
CVE-2025-8050

External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.  The vulnerability could

6.5
CVE-2025-60790

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is

6.5
CVE-2025-60427

LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can

5.3
CVE-2025-12031

HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the

5.0
CVE-2025-62763

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

4.3
CVE-2025-62605

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifia

6.1
CVE-2025-62598

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1,

6.1
CVE-2025-62597

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1,

4.3
CVE-2025-62595

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to

4.3
CVE-2025-60511

Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability

5.4
CVE-2025-60506

Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An

6.5
CVE-2025-62250

Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.

6.5
CVE-2025-61194

daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.

6.5
CVE-2025-61181

daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.

6.1
CVE-2025-60280

Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code

6.1
CVE-2025-60934

Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Perfor

6.1
CVE-2025-60933

Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Perf

6.1
CVE-2025-60932

Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Per

5.3
CVE-2025-59438

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

6.1
CVE-2025-57521

Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application

6.5
CVE-2025-56450

Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter

5.3
CVE-2020-36855

A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the

6.5
CVE-2025-6239

Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di

5.2
CVE-2025-7473

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

6.1
CVE-2025-10612

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Info

5.4
CVE-2025-26392

SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using

6.2
CVE-2025-54764

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i

6.1
CVE-2025-12001

Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B

5.0
CVE-2025-11536

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver

6.5
CVE-2025-60783

There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerabilit

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started