Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 532/1777
4.6
CVE-2025-31992

HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters

5.3
CVE-2025-52616

HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack pla

4.7
CVE-2025-11628

A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This a

4.2
CVE-2025-31997

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypas

6.3
CVE-2025-11613

A vulnerability was found in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file

6.3
CVE-2025-11612

A vulnerability has been found in code-projects Simple Food Ordering System 1.0. This impacts an unknown function of the

6.3
CVE-2025-11611

A weakness has been identified in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the fil

6.3
CVE-2025-11610

A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown proce

6.3
CVE-2025-11607

A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_m

6.3
CVE-2025-11606

A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The

6.3
CVE-2025-11605

A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /

6.3
CVE-2025-11603

A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of t

6.3
CVE-2025-11600

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown func

6.3
CVE-2025-11597

A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of t

6.8
CVE-2025-9975

The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5

4.9
CVE-2025-9950

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and

4.9
CVE-2025-9947

The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versio

4.3
CVE-2025-9626

The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1

4.3
CVE-2025-9621

The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an

4.3
CVE-2025-8682

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on th

5.3
CVE-2025-8484

The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 throug

6.4
CVE-2025-7652

The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode

6.2
CVE-2025-58301

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect

6.2
CVE-2025-58300

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect

5.5
CVE-2025-58293

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe

5.9
CVE-2025-58289

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe

4.7
CVE-2025-11595

A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function o

4.3
CVE-2025-10376

The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t

4.3
CVE-2025-10375

The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t

6.4
CVE-2025-10190

The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortco

6.5
CVE-2025-10175

The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and

6.4
CVE-2025-10167

The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi

6.4
CVE-2025-10129

The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p

5.9
CVE-2025-58297

Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availabili

5.9
CVE-2025-58295

Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may aff

5.5
CVE-2025-58288

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av

5.3
CVE-2025-11594

A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f

5.3
CVE-2025-11518

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver

4.3
CVE-2025-11254

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in

4.7
CVE-2025-11167

The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulner

6.4
CVE-2025-9496

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modifie

5.3
CVE-2025-9196

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to S

6.4
CVE-2025-11197

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in

4.9
CVE-2025-10185

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderb

4.9
CVE-2025-10048

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up

6.3
CVE-2025-11593

A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin

6.3
CVE-2025-11592

A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edi

6.3
CVE-2025-11591

A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknow

5.3
CVE-2025-58285

Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service c

5.9
CVE-2025-58284

Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started