Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 620/1777
6.8
CVE-2025-54630

:Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulne

6.7
CVE-2025-54629

Race condition issue occurring in the physical page import process of the memory management module. Impact: Successful e

5.3
CVE-2025-54628

Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of thi

4.4
CVE-2025-54626

Pointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect

6.7
CVE-2025-54625

Race condition vulnerability in the kernel file system module. Impact: Successful exploitation of this vulnerability may

5.7
CVE-2025-54624

Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerab

6.8
CVE-2025-8656

Kenwood DMX958XR Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows physically pre

6.8
CVE-2025-8655

Kenwood DMX958XR libSystemLib Command injection Remote Code Execution Vulnerability. This vulnerability allows physicall

6.8
CVE-2025-8652

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical

6.8
CVE-2025-8651

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical

6.8
CVE-2025-8650

Kenwood DMX958XR libSystemLib Command Injection Remote Code Execution Vulnerability. This vulnerability allows physicall

6.8
CVE-2025-8649

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical

6.8
CVE-2025-8648

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8647

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8646

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8645

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8644

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8643

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8642

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8641

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8640

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8639

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8638

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8637

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8636

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8635

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8634

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8633

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8632

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8631

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8630

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8629

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8628

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.4
CVE-2025-7502

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several sh

6.5
CVE-2025-6986

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via th

6.4
CVE-2025-6690

The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ paramet

6.4
CVE-2025-6259

The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view short

6.4
CVE-2025-6256

The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ paramete

6.3
CVE-2025-54623

Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may

5.3
CVE-2025-54621

Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory r

5.5
CVE-2025-54620

Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerabi

5.3
CVE-2025-54619

Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause i

5.7
CVE-2025-54618

Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerabil

6.8
CVE-2025-54617

Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability c

4.0
CVE-2025-54616

Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability m

6.2
CVE-2025-54615

Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of thi

6.2
CVE-2025-54614

Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may af

5.9
CVE-2025-54613

Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may

5.9
CVE-2025-54612

Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may

5.4
CVE-2025-54610

Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started