Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 595/1777
5.4
CVE-2025-9650

A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This affects the func

4.3
CVE-2025-9647

A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin

5.4
CVE-2025-40709

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura

5.4
CVE-2025-40708

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura

5.4
CVE-2025-40707

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura

5.4
CVE-2025-40706

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura

5.4
CVE-2025-40705

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura

5.4
CVE-2025-40704

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura

5.4
CVE-2025-40703

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura

5.4
CVE-2025-40702

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura

6.5
CVE-2025-9217

The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36

6.4
CVE-2025-8150

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewr

5.9
CVE-2024-13987

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Se

4.3
CVE-2025-54777

Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Emai

6.5
CVE-2025-9441

The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all ve

4.3
CVE-2025-9374

The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to

6.4
CVE-2025-8619

The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map

6.4
CVE-2025-8290

The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver

4.3
CVE-2025-8147

The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on th

6.5
CVE-2025-53507

Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploit

5.3
CVE-2025-9619

A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of

6.3
CVE-2025-9609

A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educac

6.3
CVE-2025-9608

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Formu

6.3
CVE-2025-9607

A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the fil

6.3
CVE-2025-9606

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionali

5.3
CVE-2025-39246

There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated u

4.7
CVE-2025-39245

There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject e

6.3
CVE-2025-9603

A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file

6.3
CVE-2025-9602

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. P

4.0
CVE-2025-54142

Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because the

5.5
CVE-2025-43284

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sono

4.3
CVE-2024-54568

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously

5.5
CVE-2024-54554

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ab

4.3
CVE-2025-9595

A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown

5.5
CVE-2025-58061

OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernete

5.3
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put

6.3
CVE-2025-9586

A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of

6.3
CVE-2025-9585

A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /u

6.3
CVE-2025-9584

A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the fil

6.3
CVE-2025-9583

A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the

6.3
CVE-2025-9582

A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Execut

6.3
CVE-2025-9581

A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt.

6.3
CVE-2025-9580

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform

6.3
CVE-2025-9579

A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/

5.3
CVE-2025-57220

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privilege

5.3
CVE-2025-57219

Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attacke

6.3
CVE-2025-9575

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0

4.4
CVE-2025-9195

Improper input validation in firmware of some Solidigm DC Products may allow an attacker with local access to cause a De

5.8
CVE-2025-58049

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions fro

5.3
CVE-2025-57218

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g paramet

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started