Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 757/1777
6.3
CVE-2025-3241

A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an u

5.3
CVE-2025-3237

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown

5.3
CVE-2025-3236

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects un

6.3
CVE-2025-3235

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This aff

5.3
CVE-2025-2245

A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in

4.7
CVE-2025-3229

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been declared as critical. This vuln

6.3
CVE-2025-3215

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this

5.4
CVE-2025-3087

Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts

5.4
CVE-2025-2797

The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,

4.3
CVE-2025-3214

A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability i

6.3
CVE-2025-3211

A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affect

6.4
CVE-2025-2836

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu

5.9
CVE-2025-2279

The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting

4.4
CVE-2024-13898

The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl

6.3
CVE-2025-3210

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected

6.3
CVE-2025-3209

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affec

6.3
CVE-2025-3208

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Aff

6.1
CVE-2025-3191

All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button whi

6.3
CVE-2025-3207

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue a

6.3
CVE-2025-3206

A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. This vulnerab

6.3
CVE-2025-3205

A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an un

6.3
CVE-2025-3204

A vulnerability, which was classified as critical, has been found in CodeAstro Car Rental System 1.0. Affected by this i

4.3
CVE-2025-3203

A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the func

5.3
CVE-2025-3196

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the

6.5
CVE-2025-26401

Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authen

5.8
CVE-2025-25061

Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, whi

5.3
CVE-2025-24317

Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, whi

4.3
CVE-2025-24310

Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote

4.7
CVE-2025-29796

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker

4.3
CVE-2025-25001

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)

4.3
CVE-2025-0279

HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal

4.3
CVE-2025-0278

HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reve

6.5
CVE-2024-47217

An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated

5.0
CVE-2025-3177

A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of

5.3
CVE-2025-31486

Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By

5.3
CVE-2025-31127

Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25

5.3
CVE-2025-31126

Element X iOS is a Matrix iOS Client provided by Element. In Element X iOS version between 1.6.13 and 25.03.7, the entit

5.0
CVE-2025-3169

A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unkno

6.5
CVE-2025-3167

A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some

5.3
CVE-2025-3166

A vulnerability classified as critical was found in code-projects Product Management System 1.0. This vulnerability affe

5.3
CVE-2023-47639

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messa

5.3
CVE-2025-3165

A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of

4.7
CVE-2025-3164

A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected

5.3
CVE-2025-3163

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerabi

5.3
CVE-2025-3162

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function

5.4
CVE-2025-0272

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H

5.3
CVE-2025-3159

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the

5.3
CVE-2025-3158

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by

6.5
CVE-2025-32053

A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead t

6.5
CVE-2025-32052

A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started