Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 734/1777
6.5
CVE-2025-46420

A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when pars

5.3
CVE-2021-47664

Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames.

6.4
CVE-2025-3832

The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in al

4.2
CVE-2025-3793

The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plu

6.5
CVE-2025-3280

The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio

6.4
CVE-2025-2579

The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up

6.4
CVE-2025-2543

The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up

4.3
CVE-2025-1284

The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable

5.3
CVE-2024-13307

The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of d

6.5
CVE-2025-0639

An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions fro

4.3
CVE-2024-12244

An issue has been discovered in access controls could allow users to view certain restricted project information even wh

6.5
CVE-2025-41395

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by th

6.5
CVE-2025-35965

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity o

5.5
CVE-2025-32730

Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co.,

4.8
CVE-2025-1453

The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could

4.4
CVE-2025-3435

The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_foote

6.7
CVE-2025-1976 KEV

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can

5.9
CVE-2025-46419

Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.

4.3
CVE-2025-27581

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role t

4.3
CVE-2025-25045

IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical erro

6.3
CVE-2024-22351

IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user

5.5
CVE-2025-46400

In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input

5.5
CVE-2025-46399

A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline fu

5.5
CVE-2025-46398

In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation v

4.3
CVE-2025-3907

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue a

6.1
CVE-2025-3902

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class

6.1
CVE-2025-3901

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap S

6.1
CVE-2025-3900

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox al

6.5
CVE-2025-2772

BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulner

5.3
CVE-2025-2771

BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp

6.5
CVE-2025-2770

BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability al

6.8
CVE-2025-2763

CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability

6.1
CVE-2025-29526

A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allow

6.5
CVE-2025-28017

TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING param

6.5
CVE-2025-1522

PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remo

6.5
CVE-2025-1521

PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allo

6.5
CVE-2024-47829

pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shorten

5.8
CVE-2025-43716

A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to

6.8
CVE-2025-2703

The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modif

6.4
CVE-2025-1054

The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scrip

5.4
CVE-2024-10306

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <L

5.3
CVE-2025-2595

An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization templa

6.5
CVE-2025-0618

A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a spec

6.1
CVE-2025-1056

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the

5.9
CVE-2025-0926

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to

6.8
CVE-2025-37088

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions

5.5
CVE-2025-27087

A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Se

6.5
CVE-2025-29743

D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

6.1
CVE-2025-26159

Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of cr

4.6
CVE-2025-31328

SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated us

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started