Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 543/1777
4.9
CVE-2025-52866

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52862

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52860

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52859

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52858

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52857

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52855

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52854

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52853

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.6
CVE-2025-52654

HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output w

4.9
CVE-2025-52433

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52432

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

6.5
CVE-2025-52429

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver

4.9
CVE-2025-52428

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52427

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52424

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

6.5
CVE-2025-48730

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver

4.9
CVE-2025-48729

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-48728

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-48727

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-48726

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-47214

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-47213

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-47211

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

6.5
CVE-2025-47210

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.3
CVE-2025-46819

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user

6.0
CVE-2025-46818

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user

6.5
CVE-2025-44012

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

6.5
CVE-2025-44011

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-44010

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-44009

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-44008

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-44007

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

6.5
CVE-2025-44006

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

6.5
CVE-2025-33040

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

6.5
CVE-2025-33039

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

6.5
CVE-2025-33034

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

6.1
CVE-2021-42193

nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the prod

6.5
CVE-2025-57423

A SQL injection vulnerability was discovered in the /articles endpoint of MyClub 0.5, affecting the query parameters Con

4.7
CVE-2025-55971

TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to

6.1
CVE-2025-60454

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis

6.1
CVE-2025-60453

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis

6.1
CVE-2025-60452

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis

6.1
CVE-2025-60451

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis

6.1
CVE-2025-60450

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exis

4.9
CVE-2025-60449

An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.p

6.1
CVE-2025-60448

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due

5.9
CVE-2025-60447

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in t

6.1
CVE-2025-60445

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exis

5.9
CVE-2025-10609

Use of Hard-coded Credentials vulnerability in Logo Software Inc. TigerWings ERP allows Read Sensitive Constants Within

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started