Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 540/1777
6.5
CVE-2025-61766

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu

5.7
CVE-2025-60969

Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00

6.1
CVE-2025-60961

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V

6.6
CVE-2025-0038

In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firm

6.4
CVE-2025-61765

python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerab

6.5
CVE-2025-61224

Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra

5.4
CVE-2025-61198

A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Opt

5.3
CVE-2025-11337

A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown

5.3
CVE-2025-11336

A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected

4.7
CVE-2025-11335

A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_

4.7
CVE-2025-11331

A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic

6.3
CVE-2025-11330

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown fu

4.7
CVE-2025-0609

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Softwa

5.5
CVE-2025-0608

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forc

4.3
CVE-2025-0607

Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affe

6.0
CVE-2025-0606

Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing

4.3
CVE-2025-9914

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an

4.5
CVE-2025-9913

JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerab

6.5
CVE-2025-58591

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, mak

6.5
CVE-2025-58590

It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.

6.5
CVE-2025-58587

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short

5.3
CVE-2025-58586

For failed login attempts, the application returns different error messages depending on whether the login failed due to

5.3
CVE-2025-58585

Multiple endpoints with sensitive information do not require authentication, making the application susceptible to infor

5.3
CVE-2025-58584

In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be s

5.3
CVE-2025-58583

The application provides access to a login protected H2 database for caching purposes. The username is prefil

5.3
CVE-2025-58582

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is

4.3
CVE-2025-58581

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and metho

6.5
CVE-2025-58580

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation

5.3
CVE-2025-58579

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making t

6.3
CVE-2025-9710

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modificatio

4.3
CVE-2025-9703

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sa

4.3
CVE-2025-11321

A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown functi

6.3
CVE-2025-11320

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function up

6.3
CVE-2025-11319

A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16

4.3
CVE-2025-11306

A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the

6.3
CVE-2025-11304

A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown function

6.3
CVE-2025-11303

A vulnerability was detected in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/mp. Performi

6.3
CVE-2025-11298

A vulnerability was determined in Belkin F9K1015 1.00.10. Impacted is an unknown function of the file /goform/formSetWan

6.3
CVE-2025-11292

A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetS

4.3
CVE-2025-11291

A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts a

5.6
CVE-2025-11290

A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret H

5.8
CVE-2025-8917

A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and h

6.3
CVE-2025-11288

A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi

4.7
CVE-2025-11286

A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controlle

6.3
CVE-2025-11285

A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the

5.0
CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ o

5.5
CVE-2025-11279

A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing

4.3
CVE-2025-11278

A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of

5.3
CVE-2025-11277

A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternR

5.3
CVE-2025-11275

A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started