Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 567/1777
5.3
CVE-2025-10493

The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via t

6.3
CVE-2025-10634

A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C

6.3
CVE-2025-10629

A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file ht

6.3
CVE-2025-10628

A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgib

6.3
CVE-2025-10627

A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the fi

6.3
CVE-2025-10626

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. Affected by this issue is some unknown function

6.7
CVE-2025-23337

NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a mal

6.3
CVE-2025-10625

A vulnerability was detected in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unk

4.4
CVE-2025-23336

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of

6.3
CVE-2025-10620

A flaw has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of th

4.6
CVE-2025-59415

Frappe Learning is a learning system that helps users structure their content. In versions 2.34.1 and below, there is a

6.3
CVE-2025-10619

A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of th

6.3
CVE-2025-10618

A security vulnerability has been detected in itsourcecode Online Clinic Management System 1.0. Affected by this issue i

6.3
CVE-2025-10617

A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown

6.3
CVE-2025-10616

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file

5.3
CVE-2025-59354

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 us

5.3
CVE-2025-59351

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return

5.3
CVE-2025-59350

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access contro

6.5
CVE-2025-59347

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disab

5.3
CVE-2025-59346

Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a

6.1
CVE-2025-37122

A vulnerability in the web-based management interface of network access control services could allow an unauthenticated

6.3
CVE-2025-10615

A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /adm

4.3
CVE-2025-10614

A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This a

6.5
CVE-2025-56648

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPReque

6.3
CVE-2025-10613

A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown functi

6.3
CVE-2025-10608

A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file

4.4
CVE-2025-59339

The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording tt

5.3
CVE-2025-58767

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing

6.2
CVE-2025-58431

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earl

4.3
CVE-2025-10607

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the fil

4.3
CVE-2025-10606

A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file

4.3
CVE-2025-10605

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the fi

5.3
CVE-2025-35436

CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote

4.3
CVE-2025-35435

CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could caus

4.2
CVE-2025-35434

CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with acces

5.0
CVE-2025-35433

CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a

5.3
CVE-2025-35432

CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker

5.4
CVE-2025-35431

CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify L

5.0
CVE-2025-35430

CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'

6.3
CVE-2025-10602

A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknow

6.5
CVE-2025-9862

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue aff

6.5
CVE-2025-57055

WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An

6.3
CVE-2025-54390

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (

6.3
CVE-2025-10595

A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is so

4.7
CVE-2023-53368

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix race issue between cpu buffer write an

5.5
CVE-2023-53367

In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: fix mem leak in capture user mapp

5.5
CVE-2023-53366

In the Linux kernel, the following vulnerability has been resolved: block: be a bit more careful in checking for NULL b

5.5
CVE-2023-53365

In the Linux kernel, the following vulnerability has been resolved: ip6mr: Fix skb_under_panic in ip6mr_cache_report()

5.5
CVE-2023-53364

In the Linux kernel, the following vulnerability has been resolved: regulator: da9063: better fix null deref with parti

5.5
CVE-2023-53362

In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: don't assume child devices are all fsl

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started