Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 654/1777
5.0
CVE-2025-52925

In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka S

6.1
CVE-2024-11405

The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email a

6.3
CVE-2025-5692

The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili

4.3
CVE-2025-6600

An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attack

5.4
CVE-2025-46259

Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrect

6.5
CVE-2025-27153

Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper acces

5.8
CVE-2025-53103

JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test

5.7
CVE-2025-52294

Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypa

6.1
CVE-2025-45083

Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental p

6.1
CVE-2025-34080

The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functi

6.5
CVE-2025-50641

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId

6.5
CVE-2025-50405

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and

5.3
CVE-2025-50404

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly use

5.3
CVE-2025-6920

A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/*

4.8
CVE-2025-36582

Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorit

4.3
CVE-2025-6951

A vulnerability classified as problematic was found in SAFECAM X300 up to 20250611. This vulnerability affects unknown c

6.1
CVE-2025-5314

The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to DOM-Based Ref

5.4
CVE-2025-49483

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure.

5.4
CVE-2025-49482

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure.

5.4
CVE-2025-49481

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router modules allows Resource Leak Exposure.

6.5
CVE-2025-6224

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certific

5.4
CVE-2025-49491

Improper Resource Shutdown or Release vulnerability in ASR Falcon_Linux、Kestrel、Lapwing_Linux on Linux (traffic_stat mod

5.4
CVE-2025-49488

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router components allows Resource Leak Ex

6.4
CVE-2025-6756

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's U

5.4
CVE-2025-49490

Resource leak vulnerability in ASR180x in router allows Resource Leak Exposure. This vulnerability is associated with p

5.4
CVE-2025-49489

Improper Resource Shutdown or Release vulnerability in ASR Falcon_Linux、Kestrel、Lapwing_Linux on Linux (con_mgr compon

5.4
CVE-2025-5072

Resource leak vulnerability in ASR180x、ASR190x in con_mgr allows Resource Leak Exposure.This issue affects Falcon_Linux、

6.8
CVE-2025-6081

Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earli

5.4
CVE-2025-53096

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks p

5.4
CVE-2025-36056

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0

6.1
CVE-2025-2141

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0

6.3
CVE-2025-6930

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown fu

6.3
CVE-2025-6929

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects som

5.9
CVE-2025-52997

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ

4.5
CVE-2025-52901

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ

5.8
CVE-2025-52491

Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

5.8
CVE-2025-49493

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

5.3
CVE-2025-6925

A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerabilit

6.3
CVE-2025-6915

A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by t

5.4
CVE-2025-52896

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could uploa

4.3
CVE-2025-47871

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr

5.4
CVE-2025-46702

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr

6.3
CVE-2025-6914

A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability

6.3
CVE-2025-6913

A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown fu

4.6
CVE-2024-12915

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Sof

6.3
CVE-2025-6912

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been rated as critical. This issue affects som

6.3
CVE-2025-6911

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability

5.4
CVE-2025-2895

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to

6.5
CVE-2023-47310

A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute

6.3
CVE-2025-6910

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been classified as critical. This affects an u

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started