Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 660/1777
6.8
CVE-2024-51984

An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled

5.3
CVE-2024-51981

An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c

5.3
CVE-2024-51980

An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open

5.3
CVE-2024-51977

An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t

4.3
CVE-2025-43880

Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may caus

6.4
CVE-2025-5585

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM E

6.3
CVE-2025-6583

A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This af

6.3
CVE-2025-6582

A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Af

6.3
CVE-2025-6581

A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vu

5.3
CVE-2025-52883

Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacke

5.4
CVE-2025-6557

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker wh

5.4
CVE-2025-6556

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass co

5.4
CVE-2025-6555

Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit hea

4.2
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions

4.2
CVE-2025-52880

Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has be

4.2
CVE-2025-53073

In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorize

5.3
CVE-2025-49147

Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 a

5.0
CVE-2025-23260

NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using t

6.1
CVE-2024-56916

In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) d

6.1
CVE-2024-56918

In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authen

6.3
CVE-2025-6570

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected

6.1
CVE-2025-50699

PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in odms/admin/view-user-q

6.1
CVE-2025-50695

PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-de

6.5
CVE-2025-50693

PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/requ

4.3
CVE-2025-6569

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vu

5.4
CVE-2025-5318

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_

5.3
CVE-2025-6566

A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the f

4.3
CVE-2025-6434

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking

6.5
CVE-2025-6431

When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing

6.1
CVE-2025-6430

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was

6.5
CVE-2025-6429

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in

4.3
CVE-2025-6428

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correc

4.3
CVE-2025-6425

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified

6.5
CVE-2025-39205

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol a

6.5
CVE-2025-39204

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface

6.5
CVE-2025-39203

A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from

6.1
CVE-2025-39201

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to

6.5
CVE-2025-1718

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device

6.4
CVE-2025-5258

The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter

5.4
CVE-2025-43877

WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be

4.3
CVE-2025-36519

Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B

6.3
CVE-2025-47943

Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-sit

4.3
CVE-2025-6552

A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the functio

4.1
CVE-2025-48470

Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scr

6.4
CVE-2025-48468

Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to

6.5
CVE-2025-48467

Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to r

4.2
CVE-2025-48462

Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block ot

5.0
CVE-2025-48461

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and

6.3
CVE-2025-6535

A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerabilit

4.2
CVE-2025-6534

A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affect

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started