Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 581/1777
4.3
CVE-2025-34173

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of direct

6.1
CVE-2025-34172

In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed af

4.3
CVE-2025-55052

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

6.1
CVE-2025-43781

Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q

5.4
CVE-2025-43775

Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 thr

6.4
CVE-2025-57665

Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, cr

5.3
CVE-2025-5500

A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file Andr

4.3
CVE-2025-59005

Missing Authorization vulnerability in frenify Categorify categorify allows Exploiting Incorrectly Configured Access Con

6.5
CVE-2025-58990

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLento

6.5
CVE-2025-58989

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 D

6.5
CVE-2025-58988

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Dolson My Tick

6.5
CVE-2025-58987

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football

6.5
CVE-2025-58985

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Addition

5.9
CVE-2025-58984

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welca

5.9
CVE-2025-58983

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Incl

5.9
CVE-2025-58982

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline'

5.4
CVE-2025-58981

Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker

5.3
CVE-2025-58980

Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Acc

5.3
CVE-2025-58979

Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control S

5.3
CVE-2025-58978

Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Inco

4.9
CVE-2025-58977

Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Ser

4.3
CVE-2025-58976

Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker

4.3
CVE-2025-58975

Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Re

5.4
CVE-2025-57540

A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter confi

5.4
CVE-2025-57539

A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Vir

5.4
CVE-2025-57538

A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of P

6.7
CVE-2025-55226

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an

6.5
CVE-2025-55225

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

4.3
CVE-2025-54917

Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a

6.7
CVE-2025-54915

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

5.5
CVE-2025-54901

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.4
CVE-2025-54252

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability

4.3
CVE-2025-54251

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result

4.9
CVE-2025-54250

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c

6.5
CVE-2025-54249

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabilit

6.5
CVE-2025-54247

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c

6.5
CVE-2025-54246

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that cou

6.7
CVE-2025-54109

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

4.3
CVE-2025-54107

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea

6.7
CVE-2025-54104

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

4.8
CVE-2025-54101

Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.

6.5
CVE-2025-54097

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.5
CVE-2025-54096

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.5
CVE-2025-54095

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.7
CVE-2025-54094

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

6.7
CVE-2025-53810

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

6.5
CVE-2025-53809

Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to

6.7
CVE-2025-53808

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

6.5
CVE-2025-53806

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa

5.5
CVE-2025-53804

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started