Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 647/1777
6.5
CVE-2025-29267

SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to ob

5.3
CVE-2024-55599

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 an

6.3
CVE-2025-7181

A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unk

6.2
CVE-2025-21433

Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

6.6
CVE-2025-21426

Memory corruption while processing camera TPG write request.

5.3
CVE-2024-53009

Memory corruption while operating the mailbox in Automotive.

4.7
CVE-2025-7177

A vulnerability was found in PHPGurukul Car Washing Management System 1.0. It has been rated as critical. Affected by th

5.4
CVE-2025-40721

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerab

6.1
CVE-2025-40720

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerab

6.1
CVE-2025-40719

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerab

6.3
CVE-2025-7175

A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unkno

4.8
CVE-2025-41223

A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All

5.3
CVE-2025-41222

A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All

5.3
CVE-2025-40742

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve

6.5
CVE-2025-40593

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control

4.3
CVE-2025-27127

A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions)

6.2
CVE-2025-23364

A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly va

5.5
CVE-2025-21009

Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to caus

5.5
CVE-2025-21008

Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory c

5.5
CVE-2025-21007

Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to caus

5.5
CVE-2025-21005

Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.

6.2
CVE-2025-21004

Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allo

4.0
CVE-2025-21003

Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to acc

6.2
CVE-2025-21002

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcast

6.2
CVE-2025-21001

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Au

6.2
CVE-2025-21000

Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.

4.1
CVE-2025-20999

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows second

5.5
CVE-2025-20998

Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to acc

6.2
CVE-2025-20997

Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to res

6.4
CVE-2025-20983

Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privilege

6.4
CVE-2025-20982

Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged

5.5
CVE-2025-38237

In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait

6.3
CVE-2025-7167

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerabilit

6.3
CVE-2025-7166

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an

6.4
CVE-2025-6743

The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attrib

6.1
CVE-2025-42956

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link wh

6.5
CVE-2025-41665

An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect de

5.2
CVE-2025-24004

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsec

5.3
CVE-2025-24002

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German C

6.3
CVE-2025-7163

A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unk

6.3
CVE-2025-7162

A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue af

5.3
CVE-2025-5957

The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthor

6.4
CVE-2025-5537

The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting v

6.3
CVE-2025-7161

A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unk

6.3
CVE-2025-7159

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue

6.3
CVE-2025-7158

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vu

6.4
CVE-2025-6244

The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Store

5.4
CVE-2025-5570

The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' para

6.5
CVE-2025-20695

In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of serv

6.5
CVE-2025-20694

In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of serv

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started