Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

43,624
Total
15
Known Exploited
Showing 21,780 of 43,624 total · Page 2/436
6.1
CVE-2026-82464

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-p

6.5
CVE-2026-82462

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token vali

5.8
CVE-2026-82477

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal netw

6.1
CVE-2026-82451

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer

5.3
CVE-2026-82449

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrep

4.2
CVE-2026-82364

A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file

4.3
CVE-2026-81346

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX

4.7
CVE-2026-81342

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied dur

4.8
CVE-2026-81026

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or s

4.1
CVE-2026-80488

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values be

4.3
CVE-2026-80311

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to th

4.9
CVE-2026-77786

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds th

6.5
CVE-2026-77010

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation che

6.5
CVE-2026-77008

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or

6.6
CVE-2026-76547

The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when impor

6.8
CVE-2026-76546

The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, al

5.3
CVE-2026-19430

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and th

6.5
CVE-2026-18234

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling be

6.5
CVE-2026-18233

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints

5.4
CVE-2026-17522

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its setti

4.8
CVE-2026-17520

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving

5.9
CVE-2026-55860

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db

5.9
CVE-2026-55859

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db

5.9
CVE-2026-55858

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3

5.9
CVE-2026-55857

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3

5.9
CVE-2026-55856

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3

6.5
CVE-2026-55855

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

5.9
CVE-2026-55854

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

5.4
CVE-2026-55779

Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() i

6.1
CVE-2026-82018

IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the G

4.3
CVE-2026-55696

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.se

6.2
CVE-2026-3686

IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limi

6.4
CVE-2026-19294

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private

4.3
CVE-2026-18545

IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat

6.5
CVE-2026-13734

Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c vali

5.9
CVE-2025-64649

IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te

5.9
CVE-2025-36290

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid

5.9
CVE-2025-36271

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a

6.1
CVE-2026-82343

A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not

6.5
CVE-2026-82306

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfi

5.3
CVE-2026-82290

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attac

5.3
CVE-2026-82276

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override exec

4.7
CVE-2026-82274

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback en

6.5
CVE-2026-82273

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when

6.5
CVE-2026-82272

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset e

6.5
CVE-2026-82271

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authen

5.4
CVE-2026-82267

Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission check

6.5
CVE-2026-82265

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing una

6.8
CVE-2026-82264

Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry pat

6.8
CVE-2026-82263

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint th

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 43,624 CVE records rated MEDIUM in our database. Of these, 15 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started