Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 557/1777
6.3
CVE-2025-10840

A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown function

6.3
CVE-2025-10839

A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. The impacted element is an u

6.4
CVE-2025-8902

The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sid

6.3
CVE-2025-10835

A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown func

6.5
CVE-2025-58915

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Req

4.3
CVE-2025-42907

SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified

6.3
CVE-2025-10828

A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. This affects an unkno

4.3
CVE-2025-10827

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown fun

6.3
CVE-2025-10826

A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. Affected by this vulnerabil

6.3
CVE-2025-10825

A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. Affected is an unknown function

5.3
CVE-2025-10824

A vulnerability was determined in axboe fio up to 3.41. This impacts the function __parse_jobs_ini of the file init.c. E

4.3
CVE-2025-10822

A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogControlle

6.5
CVE-2025-43814

In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8,

4.3
CVE-2025-43810

Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.11

4.3
CVE-2025-10821

A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of

4.3
CVE-2025-10820

A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /top

4.3
CVE-2025-10819

A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponC

4.3
CVE-2025-43806

Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2

6.5
CVE-2025-59535

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v

5.4
CVE-2025-57205

iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content

5.4
CVE-2025-57204

Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulne

5.4
CVE-2025-47910

When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than in

6.3
CVE-2025-10814

A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown fun

5.3
CVE-2025-59433

Conventional Changelog generates changelogs and release notes from a project's commit messages and metadata. Prior to ve

4.8
CVE-2025-57203

MagicProject AI version 9.1 is affected by a Cross-Site Scripting (XSS) vulnerability within the chatbot generation feat

6.5
CVE-2025-59592

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Acosta Ma

4.3
CVE-2025-59591

Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access

5.9
CVE-2025-59590

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi

6.5
CVE-2025-59589

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soleda

6.5
CVE-2025-59587

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci

6.5
CVE-2025-59586

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci

6.5
CVE-2025-59585

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci

6.5
CVE-2025-59584

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci

6.5
CVE-2025-59583

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci

5.3
CVE-2025-59582

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More

6.5
CVE-2025-59581

Missing Authorization vulnerability in VW THEMES Ibtana ibtana-visual-editor allows Exploiting Incorrectly Configured Ac

4.3
CVE-2025-59577

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Stylemix Ma

6.5
CVE-2025-59576

Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploi

6.5
CVE-2025-59574

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine W

5.3
CVE-2025-59573

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CozyThemes Cozy Blocks co

6.5
CVE-2025-59569

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer Cube

4.3
CVE-2025-59568

Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow zoho-flow allows Cross Site Request Forgery.This

5.5
CVE-2025-59567

Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Exploiting Inc

6.5
CVE-2025-59565

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Upsell O

5.5
CVE-2025-59562

Authorization Bypass Through User-Controlled Key vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Inco

4.3
CVE-2025-59561

Missing Authorization vulnerability in hashthemes Smart Blocks smart-blocks allows Exploiting Incorrectly Configured Acc

4.3
CVE-2025-59559

Missing Authorization vulnerability in payrexx Payrexx Payment Gateway for WooCommerce woo-payrexx-gateway allows Exploi

6.5
CVE-2025-59553

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coderz Studio Cust

6.5
CVE-2025-59552

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Dev Team

4.3
CVE-2025-59551

Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Cont

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started