Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 551/1777
5.3
CVE-2025-9904

Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Pr

5.9
CVE-2025-9903

Out-of-bounds write vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printe

5.9
CVE-2025-7698

Out-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer

4.3
CVE-2025-11125

A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. Affected b

6.3
CVE-2025-11121

A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the

4.3
CVE-2025-11119

A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the

6.3
CVE-2025-11114

A flaw has been found in CodeAstro Online Leave Application 1.0. Affected by this vulnerability is an unknown functional

6.3
CVE-2025-11113

A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /sig

4.3
CVE-2025-11112

A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown

6.3
CVE-2025-11104

A vulnerability was detected in CodeAstro Electricity Billing System 1.0. Affected by this issue is some unknown functio

4.7
CVE-2025-11103

A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability

6.3
CVE-2025-11100

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi

6.3
CVE-2025-11099

A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /gofo

6.3
CVE-2025-11098

A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set

6.3
CVE-2025-11097

A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device

6.3
CVE-2025-11096

A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_tra

6.3
CVE-2025-11095

A vulnerability was detected in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/dele

6.3
CVE-2025-11092

A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file

6.3
CVE-2025-11090

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected is an unknown function of the file /

6.3
CVE-2025-11088

A weakness has been identified in itsourcecode Open Source Job Portal 1.0. Impacted is an unknown function of the file /

5.3
CVE-2025-11083

A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library b

5.3
CVE-2025-11082

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-fram

4.3
CVE-2025-11080

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects

5.3
CVE-2025-11079

A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown func

6.3
CVE-2025-11078

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown

4.7
CVE-2025-11073

A vulnerability was detected in Keyfactor RG-EW5100BE EW_3.0B11P280_EW5100BE-PRO_12183019. The affected element is an un

4.7
CVE-2025-11071

A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_c

6.3
CVE-2025-11056

A flaw has been found in ProjectsAndPrograms School Management System 1.0. Affected by this vulnerability is an unknown

6.3
CVE-2025-11054

A security vulnerability has been detected in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function

4.3
CVE-2025-9944

The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an

6.1
CVE-2025-9899

The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to

4.3
CVE-2025-9898

The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi

4.3
CVE-2025-9896

The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.

4.3
CVE-2025-9894

The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1

4.3
CVE-2025-9893

The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i

4.3
CVE-2025-11051

A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow

6.3
CVE-2025-11050

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. E

5.3
CVE-2025-10954

Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic

6.3
CVE-2025-11049

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of

4.3
CVE-2025-10499

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request

4.3
CVE-2025-10498

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request

6.4
CVE-2025-8440

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in

6.1
CVE-2025-36239

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an u

6.5
CVE-2024-43192

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attack

6.5
CVE-2025-59938

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from

6.3
CVE-2025-11048

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unkno

6.3
CVE-2025-11047

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Ap

6.8
CVE-2025-57692

PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, e

6.3
CVE-2025-11041

A vulnerability has been found in itsourcecode Open Source Job Portal 1.0. Affected by this issue is some unknown functi

6.3
CVE-2025-11038

A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of t

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started