Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 681/1777
4.8
CVE-2025-3581

The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting

5.7
CVE-2025-25209

The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those

5.7
CVE-2025-25208

A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster

5.7
CVE-2025-25207

The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authori

6.3
CVE-2025-5859

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Aff

6.3
CVE-2025-5858

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. A

6.3
CVE-2025-5857

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue a

5.5
CVE-2025-27247

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

6.1
CVE-2025-27131

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

5.5
CVE-2025-26691

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

5.5
CVE-2025-24493

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.

6.3
CVE-2025-5838

A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this v

6.3
CVE-2025-5837

A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is a

6.3
CVE-2025-5836

A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formS

6.4
CVE-2025-5568

The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions

6.1
CVE-2025-5528

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via

6.4
CVE-2024-9994

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo

6.4
CVE-2024-9993

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo

5.3
CVE-2025-5814

The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to

4.0
CVE-2025-49128

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr

4.1
CVE-2025-49599

Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V

6.3
CVE-2025-5784

A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vuln

6.3
CVE-2025-5783

A vulnerability, which was classified as critical, was found in PHPGurukul Employee Record Management System 1.3. This a

6.8
CVE-2025-5751

WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerabilit

6.5
CVE-2025-33035

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t

5.5
CVE-2025-29871

An out-of-bounds read vulnerability has been reported to affect File Station 5. If a local attacker gains an administra

5.4
CVE-2024-56805

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vu

5.4
CVE-2024-50406

A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability c

6.7
CVE-2024-13087

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have

6.3
CVE-2025-5782

A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. A

6.3
CVE-2025-5780

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by

6.3
CVE-2025-5779

A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affecte

4.9
CVE-2025-0620

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an e

4.3
CVE-2025-5766

A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability a

6.5
CVE-2025-49450

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mhallmann SEPA Gir

4.3
CVE-2025-49449

Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa interactive-map-of-

4.3
CVE-2025-49446

Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.T

4.3
CVE-2025-49445

Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map interactive-uk-regional-ma

6.5
CVE-2025-49443

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris McCoy Bacon

6.5
CVE-2025-49442

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Si

5.3
CVE-2025-49441

Missing Authorization vulnerability in WP Map Plugins Interactive Regional Map of Florida interactive-map-of-florida all

4.3
CVE-2025-49440

Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master wp-security-master allows Cross Site

4.3
CVE-2025-49439

Cross-Site Request Forgery (CSRF) vulnerability in mariusz88atelierweb Atelier Create CV atelier-create-cv allows Cross

4.3
CVE-2025-49435

Cross-Site Request Forgery (CSRF) vulnerability in Hasina77 Wp Easy Allopass wordpress-easy-allopass allows Cross Site R

6.5
CVE-2025-49429

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Vide

6.5
CVE-2025-49427

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Abbi

5.5
CVE-2025-49419

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for W

5.9
CVE-2025-49333

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple

4.3
CVE-2025-49332

Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allo

6.6
CVE-2025-49329

Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started