Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 147/1777
6.8
CVE-2026-47775

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,

4.8
CVE-2026-47692

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9

5.9
CVE-2026-47221

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9

6.5
CVE-2026-47207

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9

6.5
CVE-2026-47204

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9

5.4
CVE-2026-56823

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent

5.3
CVE-2026-55686

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where

6.0
CVE-2026-48529

GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mo

5.0
CVE-2026-45407

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch comm

5.0
CVE-2026-28385

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import funct

4.9
CVE-2026-13434

A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multu

6.5
CVE-2026-9639

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticat

5.5
CVE-2026-44018

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

6.8
CVE-2026-9699

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before

5.3
CVE-2026-57665

Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.

4.3
CVE-2026-57664

Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.

5.4
CVE-2026-57661

Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.

5.3
CVE-2026-57660

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.

4.3
CVE-2026-57657

Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.

5.9
CVE-2026-57656

Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.

6.5
CVE-2026-57654

Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

5.3
CVE-2026-57652

Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.

6.5
CVE-2026-57651

Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.

6.5
CVE-2026-57650

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.

4.3
CVE-2026-57649

Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.

4.3
CVE-2026-57648

Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.

5.4
CVE-2026-57646

Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.

6.5
CVE-2026-57641

Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

4.3
CVE-2026-57640

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.

6.5
CVE-2026-57638

Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

4.3
CVE-2026-57637

Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

6.5
CVE-2026-57635

Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versio

4.3
CVE-2026-57634

Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.

5.3
CVE-2026-57633

Unauthenticated Sensitive Data Exposure in WCBoost &#8211; Products Compare <= 1.1.0 versions.

5.4
CVE-2026-57632

Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.

5.3
CVE-2026-57630

Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.

6.5
CVE-2026-57629

Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

4.9
CVE-2026-57627

Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

4.3
CVE-2026-57622

Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.

6.5
CVE-2026-57618

Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.

6.5
CVE-2026-57617

Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.

6.5
CVE-2026-57431

Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.

4.3
CVE-2026-57430

Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.

6.5
CVE-2026-57324

Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.

5.8
CVE-2026-57323

Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.

6.5
CVE-2026-57318

Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.

6.5
CVE-2026-57316

Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

6.5
CVE-2026-57313

Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.

5.8
CVE-2026-56066

Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.

6.5
CVE-2026-56048

Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <=

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started