Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 685/1777
6.1
CVE-2025-4966

The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in

4.9
CVE-2025-4964

The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter

5.5
CVE-2025-48910

Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect avail

6.7
CVE-2025-48908

Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation of this vulnerabili

6.2
CVE-2025-48907

Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availab

4.4
CVE-2025-48904

Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerabi

6.6
CVE-2025-48902

Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this

5.4
CVE-2025-2935

The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Requ

4.0
CVE-2024-58114

Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnera

4.3
CVE-2025-1778

The Art Theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'arttheme_them

6.4
CVE-2025-1777

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c

4.3
CVE-2025-36513

Cross-site request forgery vulnerability exists in surveillance cameras provided by i-PRO Co., Ltd.. If a user views a c

5.3
CVE-2025-5733

The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and in

4.3
CVE-2025-5714

A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250516. It has been classified as problematic. This affec

4.3
CVE-2024-56343

IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a speci

4.3
CVE-2024-56342

IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when

5.9
CVE-2024-22330

IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes i

5.4
CVE-2025-49012

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.1

6.3
CVE-2025-5698

A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424.

6.3
CVE-2025-5697

A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250

6.3
CVE-2025-5696

A vulnerability classified as critical was found in Brilliance Golden Link Secondary System up to 20250424. This vulnera

4.7
CVE-2025-5695

A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. This impacts the function subscribe_to_spot/subscribe

6.3
CVE-2025-5694

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as critic

6.5
CVE-2025-48133

Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Con

5.6
CVE-2025-5745

The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vec

6.3
CVE-2025-5693

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as cri

6.3
CVE-2025-5680

A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0.

5.6
CVE-2025-5702

The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vect

6.3
CVE-2025-5679

A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2

6.3
CVE-2025-5674

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by

5.4
CVE-2025-46258

Missing Authorization vulnerability in BdThemes Element Pack Pro allows Exploiting Incorrectly Configured Access Control

4.3
CVE-2025-46257

Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issu

6.3
CVE-2025-5670

A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This

6.3
CVE-2025-5669

A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability af

6.3
CVE-2025-5668

A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an

6.2
CVE-2025-49009

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers

6.5
CVE-2025-48493

The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, t

6.8
CVE-2025-5382

Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user manage

4.6
CVE-2025-47827 KEV

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptograph

5.0
CVE-2025-3768

Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenti

6.1
CVE-2025-30084

A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the

6.5
CVE-2025-27754

A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows auth

6.5
CVE-2025-27753

A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to th

5.4
CVE-2025-27445

A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allow

5.0
CVE-2025-0691

Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated u

6.3
CVE-2025-5660

A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affecte

6.3
CVE-2025-5659

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnera

6.3
CVE-2025-5658

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unkn

6.3
CVE-2025-5657

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affec

6.3
CVE-2025-5656

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been declared as critical. This vulnerab

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started