Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 690/1777
4.3
CVE-2025-5410

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability

6.3
CVE-2025-5406

A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952

4.3
CVE-2025-5404

A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c673

6.3
CVE-2025-5403

A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6

6.3
CVE-2025-33005

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated u

6.5
CVE-2025-33004

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper

4.8
CVE-2025-2896

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticat

5.4
CVE-2025-25044

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticat

6.5
CVE-2025-1499

IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext paramete

6.3
CVE-2025-5390

A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedea

6.3
CVE-2025-5389

A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is th

6.3
CVE-2025-5388

A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the functio

6.3
CVE-2025-5387

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of t

6.3
CVE-2025-5386

A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function trans

6.3
CVE-2025-5385

A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the fun

6.3
CVE-2025-5384

A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAuto

6.3
CVE-2025-5380

A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ad

4.3
CVE-2025-5379

A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects

4.3
CVE-2025-5378

A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown

4.3
CVE-2025-5377

A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issu

5.3
CVE-2025-4691

The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to I

6.3
CVE-2025-5375

A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critica

6.3
CVE-2025-5374

A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affec

6.3
CVE-2025-5373

A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulner

6.4
CVE-2025-5290

The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th

6.4
CVE-2025-3813

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_ele

6.4
CVE-2025-5292

The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Buil

6.4
CVE-2025-5285

The Product Subtitle for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmlTag’

6.4
CVE-2025-4595

The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fastspring/block-fast

6.4
CVE-2025-4590

The Daisycon prijsvergelijkers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'daisy

6.3
CVE-2025-5368

A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affe

4.7
CVE-2025-5016

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highl

5.1
CVE-2018-25111

django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.

6.5
CVE-2025-48948

Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions p

5.3
CVE-2025-1479

An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a

6.5
CVE-2025-48944

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, th

6.5
CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a

6.5
CVE-2025-48942

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, h

4.7
CVE-2025-5054

Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via

6.5
CVE-2025-48887

vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDo

6.5
CVE-2024-42191

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker

6.5
CVE-2024-42190

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker

6.8
CVE-2024-23589

Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dic

5.4
CVE-2025-3230

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate

4.2
CVE-2025-2571

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth c

4.3
CVE-2024-7097

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which

4.2
CVE-2024-7096

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin service

4.7
CVE-2025-4598

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace

5.9
CVE-2025-40909

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory

6.5
CVE-2025-1484

A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploite

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started