Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 758/1777
5.9
CVE-2025-32051

A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data UR

5.9
CVE-2025-32050

A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffe

6.5
CVE-2025-31896

Missing Authorization vulnerability in istmoplugins GetBookingsWP get-bookings-wp allows Exploiting Incorrectly Configur

6.5
CVE-2025-31893

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cheesefather Botne

5.8
CVE-2025-31876

Missing Authorization vulnerability in gunnarpayday Payday payday allows Exploiting Incorrectly Configured Access Contro

6.5
CVE-2025-31858

Missing Authorization vulnerability in matthewrubin Local Magic local-magic allows Exploiting Incorrectly Configured Acc

6.3
CVE-2025-31841

Missing Authorization vulnerability in Frank P. Walentynowicz FPW Category Thumbnails fpw-category-thumbnails allows Exp

4.9
CVE-2025-31827

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vlad.olaru Fonto fonto a

4.9
CVE-2025-31825

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pixelgrade Category Icon

6.5
CVE-2025-31800

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in publitio Publitio publit

6.5
CVE-2025-31795

Missing Authorization vulnerability in Plugin Devs Shopify to WooCommerce Migration migrate-shopify-to-woocommerce allow

5.4
CVE-2025-31794

Missing Authorization vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-woocommerce

6.5
CVE-2025-31789

Missing Authorization vulnerability in Matat Technologies TextMe SMS textme-sms-integration allows Exploiting Incorrectl

6.5
CVE-2025-31768

Missing Authorization vulnerability in OTWthemes Widget Manager Light widget-manager-light allows Accessing Functionalit

6.5
CVE-2025-31758

Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View free-product-table-for-woocom

6.4
CVE-2025-31746

Missing Authorization vulnerability in Think201 Clients clients allows Exploiting Incorrectly Configured Access Control

6.4
CVE-2025-31739

Missing Authorization vulnerability in Manuel Schmalstieg Minimalistic Event Manager minimalistic-event-manager allows E

6.5
CVE-2025-31736

Missing Authorization vulnerability in richtexteditor Rich Text Editor richtexteditor allows Exploiting Incorrectly Conf

6.5
CVE-2025-31729

Missing Authorization vulnerability in jeffikus WooTumblog woo-tumblog allows Exploiting Incorrectly Configured Access C

6.5
CVE-2025-31622

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Utkarsh Kukreti Ad

6.5
CVE-2025-31581

Missing Authorization vulnerability in Sandeep Kumar WP Video Playlist wp-video-playlist allows Exploiting Incorrectly C

5.8
CVE-2025-31558

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Greg TailPress tailpres

5.9
CVE-2025-31554

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in docxpresso Docxpresso do

6.5
CVE-2025-31541

Missing Authorization vulnerability in TuriTop TuriTop Booking System turitop-booking-system allows Exploiting Incorrect

6.5
CVE-2025-31091

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolut

6.5
CVE-2025-30916

Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all

6.5
CVE-2025-30915

Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-

6.5
CVE-2025-30596

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file i

6.4
CVE-2024-9416

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc

6.1
CVE-2025-2299

The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an

4.3
CVE-2025-3150

A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been declared as problematic.

4.4
CVE-2025-2874

The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored

5.5
CVE-2025-22007

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix error code in chan_alloc_skb_cb() T

5.5
CVE-2025-22006

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: Fix NAPI registration

5.5
CVE-2025-22005

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix memleak of nhc_pcpu_rth_output in fib_che

5.5
CVE-2025-22003

In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix out of bound read in strscpy() sourc

5.5
CVE-2025-22002

In the Linux kernel, the following vulnerability has been resolved: netfs: Call `invalidate_cache` only if implemented

5.5
CVE-2025-22000

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: drop beyond-EOF folios with the rig

4.7
CVE-2025-21998

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registratio

5.5
CVE-2025-21997

In the Linux kernel, the following vulnerability has been resolved: xsk: fix an integer overflow in xp_create_and_assig

5.5
CVE-2025-21996

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_

5.5
CVE-2025-21995

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix fence reference count leak The last

6.4
CVE-2025-1663

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge

6.4
CVE-2024-13673

The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' s

6.2
CVE-2025-30485

UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attachin

6.3
CVE-2025-3143

A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affecte

6.3
CVE-2025-3142

A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This

6.8
CVE-2025-31334

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points t

6.8
CVE-2025-2055

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in

6.3
CVE-2025-3141

A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started