Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 624/1777
6.3
CVE-2024-34328

An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.

4.4
CVE-2025-7738

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub

6.3
CVE-2025-54589

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, use

4.3
CVE-2025-8401

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all

6.3
CVE-2025-8382

A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected

6.3
CVE-2025-8381

A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This

4.3
CVE-2025-8151

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to,

4.3
CVE-2025-8068

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of

4.7
CVE-2025-8379

A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an

6.1
CVE-2025-24854

A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could al

5.4
CVE-2025-7205

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting

6.5
CVE-2025-54757

Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malici

6.5
CVE-2025-54752

Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malform

5.4
CVE-2025-41396

A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwri

5.4
CVE-2025-41391

Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a maliciou

6.1
CVE-2025-36563

Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesse

4.3
CVE-2025-8370

A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9. Affected is an unknown funct

4.3
CVE-2025-8369

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9. This issue affects some

4.3
CVE-2025-8368

A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code

4.3
CVE-2025-8367

A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9. This affects an unknown part of the

4.3
CVE-2025-8366

A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some u

6.4
CVE-2025-5720

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’

6.3
CVE-2025-8347

A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an

4.3
CVE-2025-8346

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue

6.3
CVE-2025-8345

A vulnerability classified as critical was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7.

6.3
CVE-2025-8344

A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticF

4.3
CVE-2025-8343

A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function

4.3
CVE-2025-8340

A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic.

6.5
CVE-2025-36040

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client

6.5
CVE-2025-36039

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client

4.3
CVE-2025-8335

A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an

6.5
CVE-2025-54585

GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attac

5.7
CVE-2025-54584

GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19

6.5
CVE-2025-54583

GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1

5.3
CVE-2025-54575

ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file con

6.1
CVE-2025-51954

playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability.

6.1
CVE-2025-51951

andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability.

6.5
CVE-2025-50464

A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability ar

6.5
CVE-2025-36608

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Refe

5.5
CVE-2025-30103

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Partie

6.5
CVE-2025-30480

Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerP

6.5
CVE-2025-45619

An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction

6.5
CVE-2025-25692

A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitr

6.5
CVE-2025-25691

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute ar

5.9
CVE-2025-8353

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 an

6.5
CVE-2025-54656

** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affe

5.9
CVE-2023-2593

A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory relea

4.3
CVE-2025-54573

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0

5.4
CVE-2025-53357

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that

4.3
CVE-2025-53112

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started