Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 16/1777
5.3
CVE-2026-13213

The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set uncondit

6.5
CVE-2026-77914

rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitra

5.3
CVE-2026-75099

Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through

5.3
CVE-2026-63621

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject

5.5
CVE-2026-60093

Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Came

6.5
CVE-2026-59230

Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9,

5.4
CVE-2026-67204

BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-u

5.3
CVE-2026-13343

The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (

6.4
CVE-2026-9728

The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->si

6.1
CVE-2026-65053

Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without esca

6.5
CVE-2026-39914

TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arb

5.3
CVE-2026-21755

HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or creden

4.3
CVE-2026-78250

A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component

6.5
CVE-2026-76845

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforc

6.8
CVE-2026-17033

An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert

5.3
CVE-2025-68833

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u

4.3
CVE-2026-21759

HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly.  A

6.5
CVE-2026-78323

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validat

5.3
CVE-2026-78291

Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

6.5
CVE-2026-78290

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

4.3
CVE-2026-78280

Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

5.4
CVE-2026-78279

Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.

5.3
CVE-2026-78278

Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.

4.9
CVE-2026-78277

Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.

5.4
CVE-2026-78272

Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.

6.4
CVE-2026-78269

Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.

5.3
CVE-2026-78258

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

5.9
CVE-2026-59295

It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) cond

5.4
CVE-2026-10618

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendere

5.3
CVE-2026-8173

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an aut

6.3
CVE-2026-78200

A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the

4.4
CVE-2026-78196

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn o

4.3
CVE-2026-78186

A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the

6.3
CVE-2026-78185

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function

6.3
CVE-2026-78179

A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function Se

5.3
CVE-2026-19853

NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers

6.1
CVE-2026-19852

NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers

4.5
CVE-2026-78177

A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the

6.3
CVE-2026-78166

A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmart

5.8
CVE-2026-78205

BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link

5.4
CVE-2026-78204

Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccess

6.3
CVE-2026-78160

A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing o

6.3
CVE-2026-78158

A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseReq

5.3
CVE-2026-78148

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of t

4.3
CVE-2026-78145

A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/u

6.3
CVE-2026-78144

A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vuln

6.3
CVE-2026-78142

A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown fu

4.7
CVE-2026-78140

A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/ja

5.3
CVE-2026-75922

Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unenco

6.1
CVE-2026-8630

justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the seriali

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started