Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 649/1777
6.1
CVE-2025-53526

WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php.

6.1
CVE-2025-53525

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified

5.4
CVE-2025-53497

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

5.4
CVE-2025-53491

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

6.1
CVE-2025-53377

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified

6.7
CVE-2025-1351

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another use

6.5
CVE-2025-7259

An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, whi

5.4
CVE-2025-7057

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

5.4
CVE-2025-53487

The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are ins

6.5
CVE-2025-53375

Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an

4.3
CVE-2025-53374

Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an

4.3
CVE-2025-7133

A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affec

6.5
CVE-2025-6712

MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This c

4.4
CVE-2025-6711

An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when cer

5.4
CVE-2025-53486

The WikiCategoryTagCloud extension is vulnerable to reflected XSS via the linkstyle attribute, which is improperly conca

6.3
CVE-2025-7056

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

4.7
CVE-2025-7127

A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System up to 1.0. This

6.3
CVE-2025-7126

A vulnerability, which was classified as critical, has been found in itsourcecode Employee Management System up to 1.0.

6.3
CVE-2025-7125

A vulnerability classified as critical was found in itsourcecode Employee Management System up to 1.0. Affected by this

6.3
CVE-2025-7124

A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown f

4.7
CVE-2025-7123

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been rated as critical. This issue affect

6.2
CVE-2025-6210

A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, al

6.5
CVE-2025-5472

The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive

6.1
CVE-2025-4779

lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attack

6.8
CVE-2025-3705

A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of sp

5.4
CVE-2025-3467

An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vu

5.3
CVE-2025-3264

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp

5.3
CVE-2025-3263

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp

5.3
CVE-2025-3044

A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows

6.3
CVE-2025-7121

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects

6.4
CVE-2025-24508

Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage

5.4
CVE-2025-7108

A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vul

5.3
CVE-2025-7107

A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLo

5.9
CVE-2025-53186

Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Im

6.6
CVE-2025-53185

Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access re

6.5
CVE-2025-53184

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53183

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53182

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53181

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53180

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53179

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

4.8
CVE-2025-53178

Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may

4.0
CVE-2025-53175

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil

4.0
CVE-2025-53174

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil

5.3
CVE-2025-53173

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil

4.0
CVE-2025-53172

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil

4.0
CVE-2025-53171

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil

4.0
CVE-2025-53170

Null pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vuln

5.7
CVE-2025-53168

Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful e

6.9
CVE-2025-53167

Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this v

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started