Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 743/1777
5.3
CVE-2025-24315

Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

6.5
CVE-2025-22269

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC R

6.5
CVE-2025-22268

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncann

6.4
CVE-2024-49200

An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential D

5.3
CVE-2025-31949

An authenticated attacker can obtain any plant name by knowing the plant ID.

5.3
CVE-2025-31941

An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.

5.3
CVE-2025-31933

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

5.3
CVE-2025-31357

An unauthenticated attacker can obtain a user's plant list by knowing the username.

6.5
CVE-2025-30740

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte

5.7
CVE-2025-30737

Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). The support

6.5
CVE-2025-30733

Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-

6.1
CVE-2025-30732

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported

5.5
CVE-2025-30729

Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (c

5.3
CVE-2025-30726

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported

6.7
CVE-2025-30725

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

5.4
CVE-2025-30723

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that

5.3
CVE-2025-30722

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a

4.0
CVE-2025-30721

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affecte

6.1
CVE-2025-30720

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Orders). Supported versions tha

6.1
CVE-2025-30719

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

5.4
CVE-2025-30718

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Uplo

6.5
CVE-2025-30717

Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Su

4.9
CVE-2025-30715

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions

4.8
CVE-2025-30714

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that ar

5.4
CVE-2025-30713

Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job O

5.4
CVE-2025-30711

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Uplo

4.9
CVE-2025-30710

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions

6.1
CVE-2025-30709

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte

4.9
CVE-2025-30705

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected

4.4
CVE-2025-30704

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions

5.3
CVE-2025-30702

Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that

4.9
CVE-2025-30699

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions tha

5.6
CVE-2025-30698

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

5.4
CVE-2025-30697

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo

4.9
CVE-2025-30696

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected

5.5
CVE-2025-30695

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

5.4
CVE-2025-30694

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19

5.5
CVE-2025-30693

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

6.5
CVE-2025-30692

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Attachments). Supported ver

4.8
CVE-2025-30691

Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6,

4.9
CVE-2025-30689

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-30688

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-30687

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-30685

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are

4.9
CVE-2025-30684

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are

4.9
CVE-2025-30683

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are

6.5
CVE-2025-30682

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

5.3
CVE-2025-30514

Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").

5.3
CVE-2025-30254

An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.

5.3
CVE-2025-27938

Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started