Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 742/1777
5.3
CVE-2025-3247

The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via th

4.8
CVE-2024-10680

The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could

5.3
CVE-2025-3668

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability

5.3
CVE-2025-3667

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the

5.5
CVE-2025-22018

In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_

5.3
CVE-2025-3666

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is

5.3
CVE-2025-3665

A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vul

5.3
CVE-2025-3664

A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the f

5.3
CVE-2025-3663

A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue a

6.4
CVE-2025-2314

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v

6.1
CVE-2024-13452

The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an

6.7
CVE-2025-30100

Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 contain an Improper Access Control Vulnerability. A low pr

5.3
CVE-2025-32385

EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to displ

5.4
CVE-2025-32388

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsa

4.6
CVE-2025-25458

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

4.6
CVE-2025-25453

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.

5.6
CVE-2025-22911

RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.

5.3
CVE-2025-32782

Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently u

5.3
CVE-2025-31950

An unauthenticated attacker can obtain EV charger energy consumption information of other users.

5.3
CVE-2025-31945

An unauthenticated attacker can obtain other users' charger information.

5.3
CVE-2025-31654

An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").

6.5
CVE-2025-31360

Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.

5.3
CVE-2025-31147

Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

6.5
CVE-2025-30982

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookPr

5.4
CVE-2025-30966

Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a throu

6.5
CVE-2025-30512

Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g.

5.3
CVE-2025-30257

Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.

5.3
CVE-2025-27929

Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.

5.3
CVE-2025-27927

An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

6.8
CVE-2025-27892

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE:

5.3
CVE-2025-27719

Unauthenticated attackers can query an API endpoint and get device details.

5.3
CVE-2025-27575

An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.

5.3
CVE-2025-27565

An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

5.3
CVE-2025-27561

Unauthenticated attackers can rename "rooms" of arbitrary users.

6.5
CVE-2025-26998

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B

6.5
CVE-2025-26996

Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets a

6.5
CVE-2025-26951

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in covertnine C9 Bloc

6.5
CVE-2025-26950

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonsPress Nepali

6.5
CVE-2025-26934

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphthemes Glossy

6.5
CVE-2025-26930

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Home S

6.5
CVE-2025-26919

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainá tai

6.5
CVE-2025-26906

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Del

4.3
CVE-2025-26903

Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery inpost-gallery allows Cross Site Request Fo

6.5
CVE-2025-26880

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT S

6.5
CVE-2025-26870

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi

5.3
CVE-2025-26857

Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

6.5
CVE-2025-26749

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Addition

6.5
CVE-2025-26740

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware Spa

5.3
CVE-2025-25276

An unauthenticated attacker can hijack other users' devices and potentially control them.

5.3
CVE-2025-24850

An attacker can export other users' plant information.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started