Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 168/1777
6.5
CVE-2026-40790

Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.

6.5
CVE-2026-40782

Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.

6.5
CVE-2026-40773

Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.

6.5
CVE-2026-40743

Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.

6.4
CVE-2026-39594

Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions.

6.5
CVE-2026-39584

Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.

6.5
CVE-2026-39540

Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.

5.4
CVE-2026-39527

Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.

6.5
CVE-2026-39525

Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.

6.5
CVE-2026-39515

Subscriber Broken Access Control in Motors < 1.4.107 versions.

6.5
CVE-2026-39491

Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.

4.4
CVE-2026-39489

Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.

6.8
CVE-2026-39468

Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.

6.3
CVE-2026-39451

Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.

6.5
CVE-2026-34892

Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.

5.3
CVE-2026-25440

Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.

6.5
CVE-2025-69332

Subscriber Broken Access Control in Bookify <= 1.1.1 versions.

6.3
CVE-2025-68049

Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.

4.4
CVE-2025-60175

Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.

5.3
CVE-2026-52721

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trig

6.5
CVE-2026-52718

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse

6.5
CVE-2026-50892

Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth

5.4
CVE-2026-50876

A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HT

6.5
CVE-2026-49953

Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo

6.5
CVE-2026-39197

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv

6.1
CVE-2026-37216

Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.

6.8
CVE-2026-36933

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi

6.1
CVE-2026-36521

PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.

5.5
CVE-2026-11931

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication tok

6.3
CVE-2025-70102

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options.

5.5
CVE-2025-55663

A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attacke

5.5
CVE-2025-55661

A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial

5.5
CVE-2025-55660

A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to

5.5
CVE-2025-55652

A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers t

5.5
CVE-2025-55650

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attacker

5.5
CVE-2025-55649

A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attack

5.5
CVE-2025-55648

A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows

5.5
CVE-2025-55647

An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to c

5.5
CVE-2025-55645

A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to

5.5
CVE-2025-55644

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attacker

5.5
CVE-2025-55643

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attacke

6.5
CVE-2025-55642

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_writ

5.5
CVE-2025-55641

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows a

6.1
CVE-2026-49294

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and

6.5
CVE-2026-20262 KEV

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r

5.3
CVE-2026-9595

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts

6.5
CVE-2026-8683

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm

5.3
CVE-2026-5038

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using d

4.8
CVE-2026-10634

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_S

6.5
CVE-2025-15659

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started