Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 11/1777
6.5
CVE-2026-79124

Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sens

6.5
CVE-2026-79123

Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker

5.9
CVE-2026-79122

Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informa

6.5
CVE-2026-79120

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain

4.3
CVE-2026-79117

Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leverag

4.3
CVE-2026-79116

Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r

6.5
CVE-2026-79112

Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the ren

4.3
CVE-2026-79110

Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin

6.5
CVE-2026-79108

UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a

6.5
CVE-2026-79107

Incorrect authorization in TabGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially le

4.3
CVE-2026-79106

Improper input validation in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

4.3
CVE-2026-79105

Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypas

5.3
CVE-2026-79104

Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th

6.5
CVE-2026-79099

Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system acce

4.3
CVE-2026-79098

UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging s

4.3
CVE-2026-79095

Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin da

6.5
CVE-2026-79094

Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access rest

4.3
CVE-2026-79093

Incorrect authorization in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass

5.3
CVE-2026-79089

Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker

4.3
CVE-2026-79087

Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass system

5.1
CVE-2026-79086

Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to ob

4.3
CVE-2026-79085

Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

4.3
CVE-2026-79084

Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote a

4.3
CVE-2026-79082

Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who h

4.3
CVE-2026-79077

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system

6.5
CVE-2026-79076

Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

6.5
CVE-2026-79075

Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi

5.3
CVE-2026-79074

Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re

4.3
CVE-2026-79070

Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web

4.3
CVE-2026-79068

Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall

4.3
CVE-2026-79067

Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

4.3
CVE-2026-79065

Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

6.5
CVE-2026-79060

Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co

5.1
CVE-2026-79055

Information leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging so

4.3
CVE-2026-79051

Incorrect authorization in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin

4.3
CVE-2026-79050

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system ac

4.3
CVE-2026-79049

Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass

4.3
CVE-2026-79046

Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging

5.3
CVE-2026-79044

Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker

4.3
CVE-2026-79042

Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker levera

4.3
CVE-2026-79041

Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging

4.3
CVE-2026-79040

Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read me

6.5
CVE-2026-79038

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensit

5.3
CVE-2026-79030

Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

5.3
CVE-2026-79028

Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

6.5
CVE-2026-79024

Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

6.5
CVE-2026-79023

Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

4.3
CVE-2026-79022

UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragi

6.5
CVE-2026-79021

Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro

6.5
CVE-2026-79018

Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started