Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 556/1777
4.3
CVE-2025-9031

Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Doma

5.3
CVE-2025-41716

The web application allows an unauthenticated remote attacker to learn information about existing user accounts with the

5.3
CVE-2025-48459

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0

6.5
CVE-2025-43819

A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.

6.1
CVE-2025-43779

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024

5.9
CVE-2025-58473

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f

5.9
CVE-2025-57882

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f

6.8
CVE-2025-55038

An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Thro

5.3
CVE-2025-58069

The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerabili

4.2
CVE-2025-54855

Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability

5.0
CVE-2024-21935

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate R

5.0
CVE-2024-21927

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain

6.5
CVE-2025-56311

In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authentic

6.5
CVE-2025-57636

OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injecti

5.9
CVE-2025-58674

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows S

5.3
CVE-2025-56146

Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.

6.7
CVE-2025-54081

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineS

6.5
CVE-2025-45326

An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.p

6.5
CVE-2025-59821

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v

6.1
CVE-2025-59548

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v

5.3
CVE-2025-59547

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v

6.3
CVE-2025-59539

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v

4.3
CVE-2025-58246

Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. Th

6.5
CVE-2025-57639

OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the

6.5
CVE-2025-29084

SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu

6.5
CVE-2025-29083

SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu

6.1
CVE-2025-0209

A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due

6.1
CVE-2025-56304

Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.

6.8
CVE-2025-0663

A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Ada

4.3
CVE-2024-6429

A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain

6.8
CVE-2025-5717

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input valida

5.4
CVE-2025-57407

A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticat

4.8
CVE-2025-4760

An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper valida

6.5
CVE-2024-4598

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich me

6.5
CVE-2025-9342

Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privile

5.3
CVE-2025-7106

danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `c

6.3
CVE-2025-10848

A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown p

6.3
CVE-2025-10846

A vulnerability was determined in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /m

6.3
CVE-2025-10845

A vulnerability was found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Componente

6.3
CVE-2025-10844

A vulnerability has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality o

6.5
CVE-2025-10548

The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the insta

5.5
CVE-2025-39887

In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix null-ptr-deref in bitmap_parse

5.5
CVE-2025-39886

In the Linux kernel, the following vulnerability has been resolved: bpf: Tell memcg to use allow_spinning=false path in

5.5
CVE-2025-39885

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix recursive semaphore deadlock in fiemap c

4.7
CVE-2025-39884

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix subvolume deletion lockup caused by inod

5.5
CVE-2025-39879

In the Linux kernel, the following vulnerability has been resolved: ceph: always call ceph_shift_unused_folios_left()

5.5
CVE-2025-39878

In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash after fscrypt_encrypt_pagecache_blo

5.5
CVE-2025-39876

In the Linux kernel, the following vulnerability has been resolved: net: fec: Fix possible NPD in fec_enet_phy_reset_af

5.5
CVE-2025-39875

In the Linux kernel, the following vulnerability has been resolved: igb: Fix NULL pointer dereference in ethtool loopba

5.5
CVE-2025-39874

In the Linux kernel, the following vulnerability has been resolved: macsec: sync features on RTM_NEWLINK Syzkaller man

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started