Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 661/1777
6.1
CVE-2025-34032

A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the

5.6
CVE-2025-6533

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected

4.3
CVE-2025-6532

A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerabili

4.3
CVE-2025-6531

A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability

4.8
CVE-2025-6530

A vulnerability was found in 70mai M300 up to 20250611. It has been classified as problematic. This affects an unknown p

4.3
CVE-2025-6528

A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerabilit

4.3
CVE-2025-6525

A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code

6.4
CVE-2025-49574

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1,

5.7
CVE-2021-47688

In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functional

6.3
CVE-2025-6518

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the functio

6.3
CVE-2025-6517

A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add

5.3
CVE-2025-6516

A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function

5.8
CVE-2025-52967

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

4.8
CVE-2025-52879

In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible

4.3
CVE-2025-52878

In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions

4.8
CVE-2025-52877

In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

5.4
CVE-2025-52876

In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

5.4
CVE-2025-52875

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

6.1
CVE-2025-48700 KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vul

4.3
CVE-2023-47298

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoi

6.4
CVE-2025-52920

Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyon

4.3
CVE-2024-3511

An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned f

5.3
CVE-2025-6493

A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/ma

5.3
CVE-2025-6492

A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is

6.3
CVE-2025-6485

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the

4.7
CVE-2025-6484

A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue

4.3
CVE-2025-6478

A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this

4.3
CVE-2025-6476

A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected i

4.3
CVE-2025-6473

A vulnerability, which was classified as problematic, was found in code-projects School Fees Payment System 1.0. This af

6.3
CVE-2025-6466

A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function s

6.3
CVE-2025-6453

A vulnerability classified as critical has been found in diyhi bbs 6.8. Affected is the function Add of the file /src/ma

4.3
CVE-2025-52923

Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.

6.3
CVE-2025-6422

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this

4.3
CVE-2025-52919

In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potent

5.0
CVE-2025-52918

Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized acces

4.3
CVE-2025-52917

The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive req

6.1
CVE-2025-1987

A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type websi

6.3
CVE-2025-6417

A vulnerability has been found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. Affected by t

6.3
CVE-2025-6416

A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected i

6.3
CVE-2025-6415

A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.1. This

6.3
CVE-2025-6414

A vulnerability classified as critical was found in PHPGurukul Art Gallery Management System 1.1. This vulnerability aff

6.3
CVE-2025-6413

A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.1. This affects an u

6.3
CVE-2025-6412

A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by th

6.3
CVE-2025-6411

A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by

6.3
CVE-2025-6410

A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected

4.3
CVE-2025-3629

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's

6.8
CVE-2025-36016

IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redire

6.4
CVE-2025-5289

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored

6.4
CVE-2025-5143

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the

6.1
CVE-2025-52552

FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable t

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started