Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 619/1777
5.3
CVE-2025-5197

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifical

6.5
CVE-2025-46391

CWE-284: Improper Access Control

6.5
CVE-2025-46389

CWE-620: Unverified Password Change

4.3
CVE-2025-46388

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

5.3
CVE-2025-8620

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all

6.5
CVE-2025-6013

Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set

5.5
CVE-2025-27072

Information disclosure while processing a packet at EAVB BE side with invalid header length.

5.5
CVE-2025-21472

Information disclosure while capturing logs as eSE debug messages are logged.

6.5
CVE-2025-21465

Information disclosure while processing the hash segment in an MBN file.

6.5
CVE-2025-21464

Information disclosure while reading data from an image using specified offset and size parameters.

6.1
CVE-2025-21457

Information disclosure while opening a fastrpc session when domain is not sanitized.

6.4
CVE-2025-7727

The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun

5.9
CVE-2025-7376

Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric GENESIS64 versions 10.97.3

5.7
CVE-2025-21021

Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers

5.7
CVE-2025-21020

Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged a

5.5
CVE-2025-21019

Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung He

4.4
CVE-2025-21018

Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bou

6.3
CVE-2025-21017

Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged att

4.3
CVE-2025-21016

Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allo

4.0
CVE-2025-21015

Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document s

4.3
CVE-2025-21014

Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers

6.2
CVE-2025-21013

Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to a

5.5
CVE-2025-21012

Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to mod

5.5
CVE-2025-21011

Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to a

6.0
CVE-2025-21010

Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to dea

4.0
CVE-2025-20990

Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access

5.4
CVE-2025-8100

The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th

6.4
CVE-2025-7498

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown W

6.4
CVE-2025-7399

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all ver

4.8
CVE-2025-54651

Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect

4.2
CVE-2025-54650

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulne

4.5
CVE-2025-54649

Vulnerability of using incompatible types to access resources in the location service. Impact: Successful exploitation o

5.4
CVE-2025-54648

Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of t

5.4
CVE-2025-54647

Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successful exploitation of t

5.1
CVE-2025-54646

Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability

5.0
CVE-2025-54645

Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successfu

6.6
CVE-2025-54644

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Succe

6.6
CVE-2025-54643

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Succe

6.7
CVE-2025-54642

Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exp

6.7
CVE-2025-54641

Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful

5.5
CVE-2025-54640

ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cau

5.5
CVE-2025-54639

ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cau

4.3
CVE-2025-8595

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the w

5.5
CVE-2025-54638

Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability m

4.4
CVE-2025-54637

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Succe

4.4
CVE-2025-54636

Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successfu

5.9
CVE-2025-54635

Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of

6.7
CVE-2025-54633

Out-of-bounds read vulnerability in the register configuration of the DMA module. Impact: Successful exploitation of thi

6.8
CVE-2025-54632

Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulner

6.7
CVE-2025-54631

Vulnerability of insufficient data length verification in the partition module. Impact: Successful exploitation of this

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started