Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 613/1777
5.5
CVE-2025-54201

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54200

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54199

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54198

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54197

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54195

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54194

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54193

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54192

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54191

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54190

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54189

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54188

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-54186

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-49562

Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could lead to disclosur

4.4
CVE-2025-36000

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This

6.5
CVE-2025-55169

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio

6.7
CVE-2025-47857

A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F

5.4
CVE-2025-43734

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025

5.9
CVE-2025-36124

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security rest

6.5
CVE-2025-32932

An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiS

6.4
CVE-2025-32766

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.

6.7
CVE-2025-27759

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in

5.3
CVE-2025-25248

An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, v

5.5
CVE-2024-52964

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For

6.8
CVE-2024-48892

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all vers

4.4
CVE-2024-40588

Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiC

6.6
CVE-2023-45584

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.

5.5
CVE-2025-53769

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

4.4
CVE-2025-53765

Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclo

6.8
CVE-2025-53736

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

6.5
CVE-2025-53728

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize

5.7
CVE-2025-53719

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl

6.5
CVE-2025-53716

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to

5.5
CVE-2025-53156

Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to discl

5.7
CVE-2025-53153

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl

5.7
CVE-2025-53148

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl

5.7
CVE-2025-53138

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl

5.5
CVE-2025-53136

Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disc

6.5
CVE-2025-50172

Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service ov

6.5
CVE-2025-50166

Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose

5.7
CVE-2025-50157

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl

5.7
CVE-2025-50156

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl

6.5
CVE-2025-50154

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p

4.3
CVE-2025-49755

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac

6.8
CVE-2025-49751

Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

5.4
CVE-2025-49745

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premi

6.7
CVE-2025-49743

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon

4.3
CVE-2025-49736

The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over

5.3
CVE-2025-49559

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started