Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 15/1777
5.3
CVE-2026-72699

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register(

6.5
CVE-2026-72698

Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing

6.5
CVE-2026-72697

Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to vali

5.3
CVE-2026-56708

Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attac

6.8
CVE-2026-56706

Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (form

6.1
CVE-2026-56704

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without

5.4
CVE-2026-34967

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in th

5.8
CVE-2026-34964

Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, wh

4.7
CVE-2026-34959

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no tru

4.3
CVE-2026-19801

The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnera

6.5
CVE-2026-15023

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection

4.3
CVE-2026-10630

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress

5.5
CVE-2026-59183

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.2
CVE-2026-55373

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.1
CVE-2026-55059

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.5
CVE-2026-78434

A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the

6.5
CVE-2026-78266

Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

6.5
CVE-2026-68516

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.5
CVE-2026-27364

Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.

6.0
CVE-2026-17113

A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed

6.8
CVE-2026-5006

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may

4.7
CVE-2026-56136

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attack

4.3
CVE-2026-55468

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 o

5.3
CVE-2026-16782

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A m

5.5
CVE-2026-16781

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerabilit

6.1
CVE-2022-30983

A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows rem

5.3
CVE-2026-78430

A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall o

4.3
CVE-2026-77923

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in

5.3
CVE-2026-77310

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prio

6.5
CVE-2026-75509

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar

6.3
CVE-2026-72714

Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled

6.3
CVE-2026-72711

The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the che

6.3
CVE-2026-72705

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may

6.3
CVE-2026-72704

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after

6.3
CVE-2026-72703

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls betwe

6.5
CVE-2026-71511

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticate

6.5
CVE-2026-71510

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers

6.6
CVE-2026-63693

Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile

6.3
CVE-2020-37268

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definiti

4.3
CVE-2026-78417

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 a

6.5
CVE-2026-75370

An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC sof

6.2
CVE-2026-71832

Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote

6.5
CVE-2026-71509

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint t

6.5
CVE-2026-71508

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows

6.5
CVE-2026-71507

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account w

6.1
CVE-2026-71503

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration templa

6.1
CVE-2026-78475

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin al

6.4
CVE-2026-76837

Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/acco

4.9
CVE-2026-71932

Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulne

4.9
CVE-2026-71920

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vul

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started