Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 720/1777
6.2
CVE-2025-46587

Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may a

5.3
CVE-2025-3281

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln

5.4
CVE-2025-3020

An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several

6.2
CVE-2024-58252

Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this

4.3
CVE-2025-4329

A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the functio

4.3
CVE-2025-4327

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The ma

5.1
CVE-2025-46586

Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect

4.3
CVE-2025-4337

The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including

4.7
CVE-2025-4310

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unk

5.3
CVE-2025-3609

The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and inclu

6.3
CVE-2025-4305

A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the f

6.2
CVE-2024-39442

In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure wi

6.3
CVE-2025-4291

A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload.

5.3
CVE-2025-1493

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticat

5.3
CVE-2025-1000

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 coul

5.3
CVE-2025-0915

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 un

5.8
CVE-2025-46813

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd

6.4
CVE-2025-46734

league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of th

6.8
CVE-2025-46730

MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-

6.5
CVE-2025-45618

Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE all

5.4
CVE-2025-46719

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.

5.4
CVE-2025-46571

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.

5.4
CVE-2025-46559

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, m

6.1
CVE-2025-46553

@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1

5.4
CVE-2025-46335

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo

6.1
CVE-2025-29573

Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms mo

5.3
CVE-2024-42213

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might

5.4
CVE-2024-42212

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request For

4.3
CVE-2025-4282

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. Th

6.3
CVE-2025-4051

Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced

5.3
CVE-2025-45239

An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.

5.4
CVE-2025-45236

A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to exe

6.5
CVE-2025-45240

foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.

6.5
CVE-2025-43915

In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10,

5.3
CVE-2025-1992

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could

4.9
CVE-2024-51991

October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authen

5.3
CVE-2024-11615

The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1

4.3
CVE-2025-4281

A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business

5.3
CVE-2025-45320

A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management

6.1
CVE-2025-27921

A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized

6.5
CVE-2025-26241

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authentica

6.5
CVE-2025-25504

An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows

4.3
CVE-2025-4316

Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even i

6.5
CVE-2025-47268

ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafte

6.1
CVE-2025-45751

SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin

6.4
CVE-2025-28168

The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs be

5.3
CVE-2025-4271

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerabi

5.3
CVE-2025-4270

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown f

6.5
CVE-2025-4269

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown proc

5.3
CVE-2025-4268

A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unkn

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started