Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 572/1777
5.5
CVE-2025-43325

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26. An app may be

5.5
CVE-2025-43321

The issue was resolved by blocking unsigned services from launching on Intel Macs. This issue is fixed in macOS Sequoia

5.5
CVE-2025-43319

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8,

6.2
CVE-2025-43318

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Tahoe 26. An app with root pri

5.5
CVE-2025-43317

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe

5.5
CVE-2025-43315

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8,

5.5
CVE-2025-43314

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m

5.5
CVE-2025-43312

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 1

5.1
CVE-2025-43311

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.

4.4
CVE-2025-43310

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonom

5.3
CVE-2025-43308

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.

4.0
CVE-2025-43307

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Tahoe 26. An

5.5
CVE-2025-43305

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta

5.5
CVE-2025-43303

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26,

5.5
CVE-2025-43302

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18.

5.5
CVE-2025-43299

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS

6.2
CVE-2025-43297

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. An app may be

5.5
CVE-2025-43295

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS

5.5
CVE-2025-43293

The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, ma

5.5
CVE-2025-43292

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7, macOS Sequoia 15

5.5
CVE-2025-43291

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Sono

5.5
CVE-2025-43285

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma

6.2
CVE-2025-43279

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 2

6.5
CVE-2025-43272

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tah

5.1
CVE-2025-43262

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. USB Restricted Mo

5.5
CVE-2025-43231

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8. An app may be able to access

5.5
CVE-2025-43208

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl

5.5
CVE-2025-43207

This issue was addressed with improved entitlements. This issue is fixed in macOS Tahoe 26. An app may be able to access

4.0
CVE-2025-43203

The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iP

5.5
CVE-2025-43190

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i

5.5
CVE-2025-31270

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl

5.5
CVE-2025-31269

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26

5.5
CVE-2025-31268

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma

5.4
CVE-2025-31254

This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processin

6.5
CVE-2025-30468

This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsin

5.5
CVE-2025-24197

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta

4.3
CVE-2025-10485

A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue i

6.3
CVE-2025-10483

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an

5.4
CVE-2025-57117

A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execut

6.1
CVE-2025-43802

Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7

5.4
CVE-2025-43797

In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update

6.3
CVE-2025-10481

A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an

6.3
CVE-2025-10480

A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown func

6.5
CVE-2025-43799

Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202

6.5
CVE-2025-43798

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-

6.3
CVE-2025-10477

A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec

5.9
CVE-2025-59154

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire’s SASL EXTERNAL mechanism for client

6.8
CVE-2025-56448

The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling

5.4
CVE-2025-45091

Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro are vulnerable to a stored Cross-Site Scripting (XSS) attack. An

5.5
CVE-2025-10475

A weakness has been identified in SpyShelter up to 15.4.0.1015. Affected is an unknown function in the library SpyShelte

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started