Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 737/1777
6.5
CVE-2025-32796

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY

6.5
CVE-2025-32795

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY

6.5
CVE-2025-32389

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC

5.3
CVE-2025-31120

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an inse

6.5
CVE-2025-27599

Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a

4.7
CVE-2025-3792

A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown

5.3
CVE-2025-3791

A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This

5.4
CVE-2025-2950

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP h

5.3
CVE-2025-3790

A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /dr

6.3
CVE-2025-32790

Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the

6.3
CVE-2024-46089

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

6.3
CVE-2024-49808

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity

6.3
CVE-2024-45651

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure w

6.4
CVE-2025-3106

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin

5.4
CVE-2025-3056

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi

5.5
CVE-2025-40325

In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard re

5.5
CVE-2025-39989

In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-

5.5
CVE-2025-39755

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_

5.5
CVE-2025-39728

In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init()

5.5
CVE-2025-38637

In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue asse

5.5
CVE-2025-38575

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_

5.5
CVE-2025-38240

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to

5.5
CVE-2025-38152

In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdow

4.7
CVE-2025-38104

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Replace Mutex with Spinlock for RLCG re

5.5
CVE-2025-38049

In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on p

5.5
CVE-2025-37925

In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type

5.5
CVE-2025-37860

In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_

6.3
CVE-2025-3783

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff

6.1
CVE-2025-3598

The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri

4.8
CVE-2025-2162

The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could all

4.4
CVE-2025-2613

The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to S

6.4
CVE-2024-13650

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before

5.4
CVE-2025-25427

A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/

4.3
CVE-2025-3124

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of

6.5
CVE-2025-29456

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in

6.5
CVE-2025-29453

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in

6.5
CVE-2025-29455

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in

6.5
CVE-2025-29454

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in

6.5
CVE-2025-29450

An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings comp

6.5
CVE-2025-29449

An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identificatio

6.3
CVE-2025-3765

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen

6.3
CVE-2025-3764

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Thi

5.3
CVE-2025-3763

A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the fu

6.2
CVE-2025-29316

An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker t

6.3
CVE-2025-29722

A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticat

6.5
CVE-2025-28101

An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to dele

5.5
CVE-2020-36789

In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree

5.4
CVE-2024-40124

Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.

6.1
CVE-2025-43014

In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation

6.9
CVE-2025-43013

In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started