Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 24/1777
4.5
CVE-2026-16724

IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through

4.3
CVE-2026-55703

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id}

5.4
CVE-2026-55519

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permiss

6.3
CVE-2026-55482

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/

5.8
CVE-2026-50550

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmi

6.5
CVE-2026-49976

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update

5.9
CVE-2026-49870

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or at

6.7
CVE-2026-19321

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerab

6.8
CVE-2026-18681

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 i

6.9
CVE-2026-16938

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9

6.5
CVE-2026-63117

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advert

5.4
CVE-2026-55564

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfre

6.5
CVE-2026-19653

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper

6.2
CVE-2026-18874

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Anothe

5.8
CVE-2026-75145

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/r

5.3
CVE-2026-49392

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 an

5.3
CVE-2026-44256

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 an

5.3
CVE-2026-44255

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an

6.5
CVE-2026-20327

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,

5.0
CVE-2026-20314

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (

6.1
CVE-2026-20302

A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to

5.4
CVE-2026-20232

A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow

5.3
CVE-2026-20177

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could

5.4
CVE-2026-62671

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login

6.3
CVE-2026-62670

Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin

6.5
CVE-2026-61842

Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to ret

6.5
CVE-2026-61690

Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipA

4.6
CVE-2026-61607

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2,

5.3
CVE-2026-44254

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 an

4.9
CVE-2026-44253

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 an

4.3
CVE-2026-76614

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel PO

6.5
CVE-2026-67268

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vul

5.5
CVE-2026-67267

Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthoriz

5.5
CVE-2026-67266

Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged a

6.6
CVE-2026-56796

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Follow

4.6
CVE-2026-54793

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Genera

5.3
CVE-2026-53452

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding.

6.5
CVE-2026-50149

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is

4.3
CVE-2026-40509

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter

5.4
CVE-2026-40508

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler

6.1
CVE-2026-40507

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handl

5.3
CVE-2026-32802

Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privilege

5.2
CVE-2026-15961

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a

6.3
CVE-2026-76239

Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing a

6.7
CVE-2026-76233

Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the d

6.7
CVE-2026-76232

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the

6.7
CVE-2026-76231

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where use

6.7
CVE-2026-76230

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-pr

6.7
CVE-2026-76229

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize man

6.7
CVE-2026-76228

Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injec

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started