Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 535/1777
6.1
CVE-2025-59997

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59996

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59995

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59994

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59993

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59992

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59991

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59990

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59989

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59988

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59987

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59986

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59985

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59984

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59983

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59982

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.1
CVE-2025-59981

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network

6.5
CVE-2025-59980

An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated,

6.1
CVE-2025-61532

Cross Site Scripting vulnerability in SVX Portal v.2.7A to execute arbitrary code via the TG parameter on last_heard_pag

6.1
CVE-2025-60302

code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, t

6.5
CVE-2025-60265

In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in user/list is not securely filtere

6.5
CVE-2025-59976

An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based aut

6.5
CVE-2025-59967

A NULL Pointer Dereference vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved

5.3
CVE-2025-59962

An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and J

6.5
CVE-2025-59958

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper N

6.8
CVE-2025-59957

An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series

6.5
CVE-2025-56426

An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, s

6.5
CVE-2025-52961

An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivit

5.9
CVE-2025-52960

A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper

4.7
CVE-2025-10282

BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious form

4.7
CVE-2025-10281

BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious f

6.5
CVE-2025-39664

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows auth

4.3
CVE-2025-32916

Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p4

4.3
CVE-2025-36225

IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user d

4.9
CVE-2025-36171

IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly vali

5.3
CVE-2023-37401

IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be truste

6.4
CVE-2025-9371

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versi

4.3
CVE-2025-2934

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, an

6.5
CVE-2025-10249

The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missin

5.5
CVE-2025-39959

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix incorrect retrival of acp_chip_

5.5
CVE-2025-39954

In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate read

5.5
CVE-2025-27049

Transient DOS while processing IOCTL call for image encoding.

6.1
CVE-2025-27045

Information disclosure while processing batch command execution in Video driver.

5.5
CVE-2025-27041

Transient DOS while processing video packets received from video firmware.

6.5
CVE-2025-27040

Information disclosure may occur while processing the hypervisor log.

6.6
CVE-2025-27039

Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.

6.3
CVE-2025-11530

A weakness has been identified in code-projects Online Complaint Site 1.0. Affected is an unknown function of the file /

6.3
CVE-2025-11523

A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSe

5.4
CVE-2025-11166

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all

6.3
CVE-2025-11516

A weakness has been identified in code-projects Online Complaint Site 1.0. Impacted is an unknown function of the file /

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started