Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 617/1777
6.5
CVE-2025-55001

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi

6.5
CVE-2025-55000

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi

5.3
CVE-2025-54998

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi

5.3
CVE-2025-55152

oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and

4.3
CVE-2025-8739

A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0 and classified as problematic. This issue affects some unkno

5.3
CVE-2025-8738

A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnera

5.3
CVE-2025-8736

A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the

4.8
CVE-2025-50928

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter

6.3
CVE-2025-50927

A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authent

6.5
CVE-2025-50468

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l

6.5
CVE-2025-50467

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l

5.8
CVE-2025-47872

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and u

6.9
CVE-2025-52586

The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryp

6.1
CVE-2025-4576

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025

6.5
CVE-2025-36023

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authent

6.3
CVE-2025-8729

A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is t

6.5
CVE-2025-8749

Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR R

5.9
CVE-2025-6572

The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does

4.3
CVE-2025-54959

Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is explo

6.3
CVE-2025-54958

Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is e

5.7
CVE-2024-58257

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com

4.5
CVE-2024-58256

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com

5.0
CVE-2024-58255

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com

5.0
CVE-2025-8708

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the

5.3
CVE-2025-8707

A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unkn

6.3
CVE-2025-8706

A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as criti

6.3
CVE-2025-8705

A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving Syst

6.3
CVE-2025-8704

A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving

6.3
CVE-2025-8703

A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This

6.1
CVE-2025-54793

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulner

6.3
CVE-2025-8702

A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0.

6.3
CVE-2025-8701

A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critic

6.5
CVE-2025-53774

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

5.6
CVE-2025-47808

In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while par

5.5
CVE-2025-47807

In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer wh

5.6
CVE-2025-47806

In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack

6.6
CVE-2025-47183

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer whil

6.3
CVE-2025-8697

A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function Stdi

6.4
CVE-2025-7195

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used

5.3
CVE-2025-51533

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access in

6.1
CVE-2023-41529

Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php

6.1
CVE-2023-41519

Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the ses

6.5
CVE-2023-40992

Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the pas

4.3
CVE-2025-54397

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Se

5.4
CVE-2025-54396

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated u

6.1
CVE-2025-54395

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configu

5.3
CVE-2025-54394

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credenti

5.4
CVE-2025-54393

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authent

6.1
CVE-2025-54392

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d

6.5
CVE-2024-42048

OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started