Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 635/1777
6.5
CVE-2025-52163

A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v

5.4
CVE-2025-33014

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web

5.3
CVE-2025-7797

A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf

6.5
CVE-2025-52168

Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 all

6.5
CVE-2025-52166

Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate

6.5
CVE-2025-52162

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the

6.5
CVE-2025-50586

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

6.5
CVE-2025-47995

Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

6.5
CVE-2025-45157

Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

5.3
CVE-2025-45156

Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users.

6.5
CVE-2025-54078

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro

6.5
CVE-2025-54077

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro

6.5
CVE-2025-54076

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro

4.4
CVE-2025-54059

melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version

6.3
CVE-2025-7788

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability

6.3
CVE-2025-7787

A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function ht

5.4
CVE-2025-46732

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.

6.5
CVE-2025-46000

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2

6.5
CVE-2025-7784

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are e

6.5
CVE-2025-46002

An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP re

5.5
CVE-2024-13175

Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. T

4.3
CVE-2025-7785

A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the fun

6.8
CVE-2025-6233

Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths

6.5
CVE-2025-6226

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization

4.2
CVE-2025-6197

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites

4.3
CVE-2024-32124

An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions loggi

6.7
CVE-2024-27779

An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version

6.5
CVE-2025-7772

The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F

4.3
CVE-2025-6726

The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing

4.4
CVE-2025-6719

The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi

6.5
CVE-2025-6717

The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin

5.3
CVE-2025-5811

The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis

6.4
CVE-2025-5800

The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ paramete

6.4
CVE-2025-5767

The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ param

6.4
CVE-2025-5754

The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via

6.4
CVE-2025-5752

The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘w

6.4
CVE-2025-7660

The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location

6.4
CVE-2025-7648

The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_b

4.9
CVE-2025-7638

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based

4.3
CVE-2025-6781

The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve

6.1
CVE-2025-6053

The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and

4.3
CVE-2025-5816

The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure

4.4
CVE-2025-7431

The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all

4.3
CVE-2025-7763

A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the functi

6.3
CVE-2025-7759

A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file mod

4.3
CVE-2025-7756

A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown fu

6.3
CVE-2025-7755

A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects

4.7
CVE-2025-23269

NVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive informat

6.3
CVE-2025-7754

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. This

6.7
CVE-2025-6249

An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with e

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started