Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 794/1777
5.5
CVE-2025-21841

In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting

5.5
CVE-2025-21840

In the Linux kernel, the following vulnerability has been resolved: thermal/netlink: Prevent userspace segmentation fau

5.5
CVE-2025-21838

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: flush gadget workqueue after dev

5.5
CVE-2025-21835

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor

5.3
CVE-2024-13904

The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions

6.5
CVE-2024-13781

The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to

6.1
CVE-2024-13431

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ref

5.3
CVE-2024-12611

The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the

5.3
CVE-2024-12610

The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a miss

6.5
CVE-2024-12609

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance'

6.5
CVE-2024-12607

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of

6.4
CVE-2025-0863

The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' s

5.5
CVE-2024-12576

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW r

6.4
CVE-2024-12809

The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortc

4.5
CVE-2025-27796

ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds acc

4.3
CVE-2025-27795

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

4.3
CVE-2025-2061

A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. Th

4.2
CVE-2025-26708

There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the Wi

4.7
CVE-2025-2054

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected

4.3
CVE-2025-0748

The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This

4.3
CVE-2024-13526

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data

6.3
CVE-2025-2053

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. Af

6.3
CVE-2025-2052

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This issue

6.3
CVE-2025-2051

A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This v

6.8
CVE-2025-1121

Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an

6.3
CVE-2025-2046

A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by

4.7
CVE-2025-2044

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected

4.7
CVE-2025-2043

A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown proces

4.3
CVE-2025-2042

A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects

6.3
CVE-2025-2041

A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected b

6.5
CVE-2024-57972

The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Wi

6.3
CVE-2025-2040

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is

4.7
CVE-2025-2039

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an

6.3
CVE-2025-2037

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vuln

6.3
CVE-2025-2036

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects a

6.5
CVE-2025-27600

FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP ver

5.4
CVE-2025-27506

NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vu

5.0
CVE-2025-26699

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap

5.3
CVE-2025-25294

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

5.4
CVE-2025-25191

Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name

6.3
CVE-2025-2035

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue

6.3
CVE-2025-2033

A vulnerability, which was classified as critical, was found in code-projects Blood Bank Management System 1.0. Affected

5.5
CVE-2025-21834

In the Linux kernel, the following vulnerability has been resolved: seccomp: passthrough uretprobe systemcall without f

5.5
CVE-2025-21833

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE T

5.5
CVE-2025-21831

In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid putting some root ports into D3 on TUXED

6.5
CVE-2025-0337

ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now

5.5
CVE-2024-58085

In the Linux kernel, the following vulnerability has been resolved: tomoyo: don't emit warning in tomoyo_write_control(

5.5
CVE-2024-58084

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qc

5.5
CVE-2024-58082

In the Linux kernel, the following vulnerability has been resolved: media: nuvoton: Fix an error check in npcm_video_ec

5.5
CVE-2024-58081

In the Linux kernel, the following vulnerability has been resolved: clk: mmp2: call pm_genpd_init() only after genpd.na

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started