Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 767/1777
6.8
CVE-2025-31680

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue

6.1
CVE-2025-31679

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Er

5.4
CVE-2025-31675

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core

4.6
CVE-2025-31673

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: fro

4.3
CVE-2025-3016

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affect

6.3
CVE-2025-3015

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the functi

5.9
CVE-2024-24456

An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentia

6.3
CVE-2025-3009

A vulnerability classified as critical was found in Jinher Network OA C6. Affected by this vulnerability is an unknown f

5.3
CVE-2025-31124

Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring un

5.5
CVE-2025-3008

A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/pop

5.5
CVE-2025-3007

A vulnerability was found in Novastar CX40 up to 2.44.0. It has been rated as critical. This issue affects the function

5.3
CVE-2025-29908

Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash colli

6.3
CVE-2025-3003

A vulnerability, which was classified as critical, was found in ESAFENET CDG 3. Affected is an unknown function of the f

5.3
CVE-2025-31125 KEV

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?

4.4
CVE-2025-31116

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor

6.1
CVE-2025-30006

Xorcom CompletePBX is vulnerable to a reflected cross-site scripting (XSS) in the administrative control panel. This

6.5
CVE-2025-2292

Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup an

6.5
CVE-2025-3048

After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks,

6.5
CVE-2025-3047

When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlink

5.3
CVE-2025-3001

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_ce

5.3
CVE-2025-30209

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access

4.8
CVE-2025-30203

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-sit

5.4
CVE-2025-30161

OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vu

4.3
CVE-2025-30155

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce

6.4
CVE-2025-30149

OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows

4.6
CVE-2025-29929

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF

6.1
CVE-2025-29772

OpenEMR is a free and open source electronic health records and medical practice management application. The POST parame

4.6
CVE-2025-29766

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF

4.3
CVE-2025-27095

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.1

5.3
CVE-2025-3000

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The

5.3
CVE-2025-2999

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.

4.7
CVE-2023-33302

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrati

5.3
CVE-2025-2998

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the func

6.3
CVE-2025-2997

A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown fu

6.5
CVE-2025-31629

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Allred Infus

5.9
CVE-2025-31627

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi

6.5
CVE-2025-31624

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LABCAT Processing

6.5
CVE-2025-31621

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidpaulsson byBr

6.5
CVE-2025-31620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in carperfer CoverMan

5.3
CVE-2025-31618

Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace connector-civicrm-mcrestface

6.5
CVE-2025-31614

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hiroprot Terms Bef

4.3
CVE-2025-31611

Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload auto-post-after-image-upload allows Ex

5.9
CVE-2025-31610

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gingerplugins Noti

4.3
CVE-2025-31609

Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured

6.5
CVE-2025-31608

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reDim GmbH CookieH

6.5
CVE-2025-31607

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flomei Simple-Audi

4.8
CVE-2025-31606

Missing Authorization vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows Exploiting Incorrectly

5.9
CVE-2025-31605

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WeblineIndia Welco

6.5
CVE-2025-31604

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com cal-com a

5.4
CVE-2025-31603

Missing Authorization vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Exploiting Incorrectly Configu

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started