Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 636/1777
5.3
CVE-2025-6230

A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLit

6.7
CVE-2025-4657

A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Le

6.7
CVE-2025-1729

A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow

5.4
CVE-2025-46102

Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Referenc

5.5
CVE-2025-51497

An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Saf

4.7
CVE-2025-54066

DiracX-Web is a web application that provides an interface to interact with the DiracX services. Prior to version 0.1.0-

6.1
CVE-2025-47189

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d

6.1
CVE-2025-53941

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to

4.6
CVE-2025-53928

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution

4.6
CVE-2025-53927

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed be

6.5
CVE-2025-40924

Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated fr

4.3
CVE-2025-3415

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p

5.3
CVE-2025-4302

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-a

5.8
CVE-2025-20288

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate

4.1
CVE-2025-20285

A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote

6.5
CVE-2025-20284

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut

6.5
CVE-2025-20283

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execut

6.3
CVE-2025-20274

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,

4.3
CVE-2025-20272

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (E

6.1
CVE-2025-53936

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro

6.1
CVE-2025-53935

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro

5.4
CVE-2025-53934

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-

5.4
CVE-2025-53933

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-

6.1
CVE-2025-53932

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro

5.4
CVE-2025-53931

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-

5.4
CVE-2025-53930

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-

5.4
CVE-2025-53929

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-

6.1
CVE-2025-53926

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including

5.4
CVE-2025-47053

Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit

5.4
CVE-2025-46959

Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit

5.4
CVE-2025-53925

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including

5.4
CVE-2024-42912

A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attac

6.9
CVE-2025-53924

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including

6.5
CVE-2025-40919

Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is gene

6.5
CVE-2025-40918

Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (clien

6.5
CVE-2025-40913

Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net:

5.3
CVE-2025-3871

Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situati

6.5
CVE-2025-50028

Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploitin

6.5
CVE-2025-49884

Missing Authorization vulnerability in alexvtn Internal Linking of Related Contents internal-linking-of-related-contents

6.5
CVE-2025-49319

Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Exploiting In

6.5
CVE-2025-48339

Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrect

6.5
CVE-2025-30959

Missing Authorization vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocomme

6.5
CVE-2025-54051

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins LightBox

6.5
CVE-2025-54050

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon

4.3
CVE-2025-54047

Missing Authorization vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Exploiting Incorrectly Con

4.3
CVE-2025-54042

Cross-Site Request Forgery (CSRF) vulnerability in Xfinitysoft WP Post Hide wp-post-hide allows Cross Site Request Forge

4.3
CVE-2025-54041

Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce

4.3
CVE-2025-54039

Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Animator scroll-triggered-animations allows Cross Site

5.4
CVE-2025-54038

Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cr

5.4
CVE-2025-54037

Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started