Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 694/1777
6.3
CVE-2025-5186

A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the

4.3
CVE-2025-5185

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been declared as

6.5
CVE-2025-40667

Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionalit

4.3
CVE-2025-5184

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been classified

4.3
CVE-2025-5182

A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as c

6.3
CVE-2025-5178

A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected i

4.3
CVE-2025-5177

A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This

5.5
CVE-2025-4057

A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between se

6.1
CVE-2025-1985

Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject H

5.3
CVE-2025-5175

A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the functio

5.3
CVE-2025-5174

A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the

5.3
CVE-2025-5173

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and

5.3
CVE-2025-41441

Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unau

6.3
CVE-2025-5171

A vulnerability, which was classified as critical, has been found in llisoft MTA Maita Training System 4.5. This issue a

6.3
CVE-2025-5170

A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects th

5.3
CVE-2025-5163

A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affe

6.3
CVE-2025-5162

A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected

4.3
CVE-2025-5161

A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulne

4.3
CVE-2025-5160

A vulnerability classified as problematic has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected is the f

4.3
CVE-2025-5159

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been rated as problematic. This issue aff

4.3
CVE-2025-5158

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been declared as problematic. This vulner

4.3
CVE-2025-5157

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects

6.3
CVE-2025-5155

A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the

6.3
CVE-2025-5152

A vulnerability classified as critical was found in Chanjet CRM up to 20250510. This vulnerability affects unknown code

5.3
CVE-2025-5151

A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This affects the function exec

6.3
CVE-2025-5150

A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the functio

5.6
CVE-2025-5149

A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the

5.3
CVE-2025-5148

A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classi

6.3
CVE-2025-5147

A vulnerability was found in Netcore NBR1005GPEV2, NBR200V2 and B6V2 up to 20250508 and classified as critical. This iss

6.3
CVE-2025-5146

A vulnerability has been found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2 and NBR200V2 up to 202505

6.3
CVE-2025-5145

A vulnerability, which was classified as critical, was found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR1

6.3
CVE-2025-5140

A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This af

5.6
CVE-2025-5139

A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown f

4.7
CVE-2025-5137

A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an unknown function of the

4.3
CVE-2025-5133

A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function o

4.3
CVE-2025-5132

A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknow

4.7
CVE-2025-5131

A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the

4.7
CVE-2025-5130

A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function up

4.7
CVE-2025-4223

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site S

5.9
CVE-2025-4602

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions u

4.4
CVE-2025-5055

The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Sc

6.1
CVE-2025-3869

The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9.

6.4
CVE-2024-13427

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri

4.3
CVE-2025-48735

A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230

6.5
CVE-2025-46176

Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotel

6.1
CVE-2025-44998

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows

4.4
CVE-2024-51102

PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili

5.4
CVE-2025-48378

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v

5.4
CVE-2025-48377

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v

5.3
CVE-2025-48375

Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equiva

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started