Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 594/1777
5.3
CVE-2025-9672

A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file A

5.3
CVE-2025-9671

A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file A

5.3
CVE-2025-9670

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src

6.3
CVE-2025-9667

A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delet

6.3
CVE-2025-9666

A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some un

6.3
CVE-2025-9665

A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown

6.5
CVE-2025-33038

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

6.5
CVE-2025-33037

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

6.5
CVE-2025-33036

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

6.5
CVE-2025-33033

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

4.9
CVE-2025-33032

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

6.5
CVE-2025-30275

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-30274

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can the

6.5
CVE-2025-30272

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can the

6.5
CVE-2025-30271

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

6.5
CVE-2025-30270

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

6.5
CVE-2025-30268

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

6.5
CVE-2025-30267

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

6.5
CVE-2025-30265

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

6.5
CVE-2025-30263

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-30262

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac

6.5
CVE-2025-30261

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

6.5
CVE-2025-30260

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re

6.5
CVE-2025-29900

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

6.5
CVE-2025-29899

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

6.5
CVE-2025-29898

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains

6.5
CVE-2025-29890

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

6.5
CVE-2025-29889

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29888

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29886

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29882

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

6.3
CVE-2025-9664

A security flaw has been discovered in code-projects Simple Grading System 1.0. Affected is an unknown function of the f

6.3
CVE-2025-9663

A vulnerability was identified in code-projects Simple Grading System 1.0. This impacts an unknown function of the file

5.4
CVE-2025-55580

SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenti

5.4
CVE-2025-55579

SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. Th

6.5
CVE-2025-29879

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29878

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29875

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29874

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

4.8
CVE-2025-22483

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remo

5.4
CVE-2024-12923

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user

4.3
CVE-2025-9656

A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unk

6.5
CVE-2025-55750

Gitpod is a developer platform for cloud development environments. In versions before main-gha.33628 for both Gitpod Cla

5.3
CVE-2025-55202

Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18

5.4
CVE-2025-55177 KEV

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Bu

5.3
CVE-2025-54877

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com

6.3
CVE-2025-9654

A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown function

5.5
CVE-2025-55304

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada

5.5
CVE-2025-54080

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada

6.3
CVE-2025-9651

A vulnerability was found in shafhasan chatbox up to 156a39cde62f78532c3265a70eda12c70907e56f. This impacts an unknown f

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started