Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 14/1777
4.3
CVE-2026-79406

A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceIm

5.6
CVE-2026-78885

A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of t

4.2
CVE-2026-78581

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Acce

5.9
CVE-2026-63074

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a C

6.5
CVE-2026-79673

Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write opera

5.5
CVE-2026-79672

Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access toke

5.5
CVE-2026-79671

Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setti

4.8
CVE-2026-79670

Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Conten

4.3
CVE-2026-79669

Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read a

5.3
CVE-2026-79668

Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows una

6.5
CVE-2026-79666

Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated us

4.8
CVE-2026-79663

Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdo

6.5
CVE-2026-79661

Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or ra

5.3
CVE-2026-79660

Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON seri

6.3
CVE-2026-78864

A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.update

5.3
CVE-2026-78684

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decod

4.9
CVE-2026-77824

The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' p

4.3
CVE-2026-75908

The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T

6.4
CVE-2026-18547

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi

5.3
CVE-2026-17587

The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass i

5.9
CVE-2026-79652

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat

6.3
CVE-2026-78863

A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/servi

5.4
CVE-2026-21754

HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthori

4.2
CVE-2026-21753

HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmainta

6.4
CVE-2026-76128

The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode At

6.1
CVE-2026-75038

UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This is

6.5
CVE-2026-78701

A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentica

6.5
CVE-2026-78322

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with a

6.4
CVE-2026-18512

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross

6.4
CVE-2026-18100

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stor

6.3
CVE-2026-78656

A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /p

6.5
CVE-2026-78470

The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0

4.3
CVE-2026-78467

The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a

4.3
CVE-2026-78466

The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and

6.8
CVE-2026-13215

The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a

6.4
CVE-2026-12561

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in a

6.4
CVE-2026-76063

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi

4.3
CVE-2026-75930

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all ve

6.4
CVE-2026-19943

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc

6.1
CVE-2026-17089

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S

6.6
CVE-2026-14280

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion i

4.4
CVE-2026-75982

The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in version

6.4
CVE-2026-75019

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress

5.3
CVE-2026-10627

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass i

6.4
CVE-2025-9878

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cr

6.5
CVE-2026-78679

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional refere

6.5
CVE-2026-78678

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --co

6.5
CVE-2026-76839

Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and

5.3
CVE-2026-75575

Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may

5.4
CVE-2026-72702

Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, w

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started