Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 769/1777
6.5
CVE-2025-30963

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSmar

5.3
CVE-2025-2992

A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is an unk

5.3
CVE-2025-2991

A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of

5.3
CVE-2025-31386

Missing Authorization vulnerability in simplepress Simple:Press simplepress allows Exploiting Incorrectly Configured Acc

4.3
CVE-2025-31376

Missing Authorization vulnerability in Mayeenul Islam NanoSupport nanosupport allows Exploiting Incorrectly Configured A

5.3
CVE-2025-2990

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown

5.3
CVE-2025-2989

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects un

4.3
CVE-2025-31410

Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Church Donation wp-church-donation allows Cross Site

4.3
CVE-2025-31406

Missing Authorization vulnerability in ELEXtensions ELEX WooCommerce Request a Quote elex-request-a-quote allows Exploit

6.5
CVE-2025-30961

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tinuzz Trackserver

6.3
CVE-2025-2985

A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affec

6.3
CVE-2025-2984

A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this is

5.5
CVE-2025-2983

A vulnerability has been found in Legrand SMS PowerView 1.x and classified as critical. Affected by this vulnerability i

6.3
CVE-2025-2982

A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown functi

4.3
CVE-2025-31417

Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Con

6.5
CVE-2025-31414

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calc

6.5
CVE-2025-31412

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetProd

6.5
CVE-2025-31043

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear

6.5
CVE-2025-30987

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBloc

6.3
CVE-2025-2978

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionalit

6.1
CVE-2025-0613

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by una

4.6
CVE-2025-24852

Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue

6.3
CVE-2025-2973

A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affect

4.3
CVE-2025-2961

A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function re

6.5
CVE-2025-2960

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affe

6.5
CVE-2025-2959

A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is th

6.5
CVE-2025-2958

A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnera

6.5
CVE-2025-2957

A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function

6.5
CVE-2025-2956

A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects th

5.3
CVE-2025-2955

A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability aff

6.3
CVE-2025-2952

A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknow

6.3
CVE-2025-2951

A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the

5.3
CVE-2025-1734

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when recei

5.3
CVE-2025-1219

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when reque

6.4
CVE-2024-11180

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Tim

5.3
CVE-2025-2840

The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers

6.5
CVE-2024-13557

The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t

4.4
CVE-2024-7577

IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation

4.3
CVE-2024-51477

IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an

5.3
CVE-2024-43186

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored

5.5
CVE-2025-28097

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

5.4
CVE-2025-28096

OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

6.5
CVE-2025-28094

shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

6.3
CVE-2025-28093

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.

6.3
CVE-2025-28092

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.

5.5
CVE-2024-58129

In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and t

5.5
CVE-2024-58128

In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus a

5.4
CVE-2025-28254

Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary c

6.5
CVE-2024-6875

A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak

6.6
CVE-2025-31164

heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via  c

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started