Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 744/1777
5.3
CVE-2025-27568

An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response

5.3
CVE-2025-24487

An unauthenticated attacker can infer the existence of usernames in the system by querying an API.

4.9
CVE-2025-21588

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte

5.4
CVE-2025-21586

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte

4.9
CVE-2025-21585

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-21584

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte

4.9
CVE-2025-21583

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte

6.1
CVE-2025-21582

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo

4.9
CVE-2025-21581

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-21580

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte

4.9
CVE-2025-21579

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff

6.7
CVE-2025-21578

Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2

6.5
CVE-2025-21577

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

5.4
CVE-2025-21576

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Su

6.5
CVE-2025-21575

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe

6.5
CVE-2025-21574

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe

6.0
CVE-2025-21573

Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli

5.9
CVE-2024-44843

An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbit

6.5
CVE-2025-32439

pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track chang

6.7
CVE-2025-1292

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacke

6.7
CVE-2025-1122

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker wi

5.5
CVE-2025-29213

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute a

4.6
CVE-2025-22903

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function

4.9
CVE-2023-5616

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use s

5.5
CVE-2025-3618

A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify

6.1
CVE-2025-33028

In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.

6.1
CVE-2025-33027

In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers

6.1
CVE-2025-33026

In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass

4.3
CVE-2025-29705

code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone

5.4
CVE-2024-42200

HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validat

6.5
CVE-2024-42189

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an

6.5
CVE-2025-32779

E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0,

5.5
CVE-2025-32776

OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu

5.7
CVE-2025-29817

Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.

5.9
CVE-2025-28198

A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the or

6.5
CVE-2025-24949

In JotUrl 2.0, is possible to bypass security requirements during the password change process.

6.5
CVE-2025-24948

In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insec

6.5
CVE-2020-18243

SQL injection vulnerability found in Enricozab CMS v.1.0 allows a remote attacker to execute arbitrary code via /hdo/hdo

6.4
CVE-2025-3523

When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only t

6.3
CVE-2025-3522

Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally.

6.5
CVE-2025-32949

This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when ex

6.3
CVE-2025-2830

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into inclu

6.5
CVE-2025-28145

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerab

6.5
CVE-2025-28144

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerabili

6.5
CVE-2025-28143

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab

6.5
CVE-2025-28142

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab

6.5
CVE-2025-27980

cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.

4.8
CVE-2025-29280

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system

6.5
CVE-2025-28136

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.

6.5
CVE-2025-3608

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially lea

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started