Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 12/1777
6.5
CVE-2026-79017

Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access r

4.3
CVE-2026-79015

Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass s

4.3
CVE-2026-79014

Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the ren

5.9
CVE-2026-79013

Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

4.3
CVE-2026-79010

Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote

4.3
CVE-2026-79009

UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri

4.3
CVE-2026-79006

Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypas

6.5
CVE-2026-79005

Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co

4.3
CVE-2026-79003

Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social en

5.3
CVE-2026-79001

Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compro

4.3
CVE-2026-79000

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote atta

5.3
CVE-2026-78991

Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r

4.3
CVE-2026-78987

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy

6.5
CVE-2026-78981

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obt

4.3
CVE-2026-78980

Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soc

4.3
CVE-2026-78979

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social

6.5
CVE-2026-78977

Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potenti

4.3
CVE-2026-78976

Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had

6.5
CVE-2026-78975

Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf

6.5
CVE-2026-78969

Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside

6.5
CVE-2026-78968

Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

6.5
CVE-2026-78967

Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

4.3
CVE-2026-78966

Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web

4.3
CVE-2026-78962

Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi

4.3
CVE-2026-78961

Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th

6.5
CVE-2026-78960

Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin

6.5
CVE-2026-78959

Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker le

5.5
CVE-2026-78957

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitiv

6.5
CVE-2026-78955

Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potential

4.3
CVE-2026-78954

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromi

6.5
CVE-2026-78947

Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin

4.3
CVE-2026-78946

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin

4.3
CVE-2026-78942

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web

4.3
CVE-2026-78940

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi

6.5
CVE-2026-78914

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read mem

5.4
CVE-2026-78912

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements v

4.3
CVE-2026-78908

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy

6.5
CVE-2026-78907

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitiv

6.5
CVE-2026-78897

Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social

4.3
CVE-2026-78896

Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-o

4.3
CVE-2026-78895

Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy

6.5
CVE-2026-78893

Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information

5.3
CVE-2026-77680

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 f

5.5
CVE-2026-65088

NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive inf

5.6
CVE-2026-65087

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf

6.8
CVE-2026-65086

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS com

5.2
CVE-2026-65085

NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper en

6.5
CVE-2026-55588

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to

5.3
CVE-2026-77585

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result

5.5
CVE-2026-68514

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started