Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 583/1777
6.5
CVE-2025-42917

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated us

5.4
CVE-2025-42915

Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic use

6.5
CVE-2025-42912

SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, re

5.0
CVE-2025-42911

SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could

6.3
CVE-2025-10121

A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipul

6.5
CVE-2025-43763

A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP

5.3
CVE-2025-58752

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files o

5.3
CVE-2025-58751

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w

6.1
CVE-2025-58452

WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified

5.9
CVE-2025-1761

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me

6.3
CVE-2025-10110

A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipul

6.5
CVE-2025-57815

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies

4.8
CVE-2025-57766

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d

6.3
CVE-2025-10106

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collec

6.3
CVE-2025-10105

A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the f

5.4
CVE-2025-53838

LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discove

6.7
CVE-2025-43722

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi

6.3
CVE-2025-10098

A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the fil

6.3
CVE-2025-10097

A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app

6.3
CVE-2025-10096

A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app

5.6
CVE-2025-40929

Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSO

5.3
CVE-2025-3212

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge

5.3
CVE-2025-10093

A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi

6.1
CVE-2014-125128

'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't p

6.1
CVE-2019-25225

`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function i

6.5
CVE-2025-58782

Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue

4.7
CVE-2025-10087

A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknow

6.3
CVE-2025-10086

A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file

6.3
CVE-2025-10085

A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects u

4.3
CVE-2025-10084

A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /a

6.3
CVE-2025-10083

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some un

4.7
CVE-2025-10081

A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/p

4.3
CVE-2025-10073

A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Ap

6.3
CVE-2025-10072

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /mat

6.3
CVE-2025-10071

A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /c

6.3
CVE-2025-10070

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/.

5.5
CVE-2025-39734

In the Linux kernel, the following vulnerability has been resolved: Revert "fs/ntfs3: Replace inode_trylock with inode_

5.5
CVE-2025-39733

In the Linux kernel, the following vulnerability has been resolved: team: replace team lock with rtnl lock syszbot rep

5.5
CVE-2025-39731

In the Linux kernel, the following vulnerability has been resolved: f2fs: vm_unmap_ram() may be called from an invalid

5.5
CVE-2025-39729

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix dereferencing uninitialized error

4.3
CVE-2025-10067

A vulnerability was detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function o

5.1
CVE-2025-36100

IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and

4.3
CVE-2025-10066

A security vulnerability has been detected in itsourcecode POS Point of Sale System 1.0. The affected element is an unkn

4.3
CVE-2025-10065

A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file

4.3
CVE-2025-10064

A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown proces

4.3
CVE-2025-10063

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of

4.7
CVE-2025-0034

Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_

6.1
CVE-2025-0010

An out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting

5.5
CVE-2025-0009

A NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentiall

6.0
CVE-2024-36346

Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to sen

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started