Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 261/1777
5.6
CVE-2026-7112

A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check

5.3
CVE-2026-7109

A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the fil

4.3
CVE-2026-7108

A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown funct

6.3
CVE-2026-7107

A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown functi

6.3
CVE-2026-7102

A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacM

4.3
CVE-2026-7095

A vulnerability was identified in code-projects Employee Management System 1.0. This affects an unknown part of the file

6.3
CVE-2026-7093

A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown f

6.3
CVE-2026-7092

A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the fi

6.3
CVE-2026-7091

A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user

5.1
CVE-2026-42371

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in

6.6
CVE-2026-3008

Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address informati

4.3
CVE-2026-7089

A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown

4.3
CVE-2026-7086

A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl

5.0
CVE-2026-7085

A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of th

6.3
CVE-2026-7084

A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/s

4.7
CVE-2026-7083

A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function q

5.3
CVE-2026-7071

A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unkn

4.3
CVE-2026-33566

There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded,

5.3
CVE-2026-7059

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file bac

6.3
CVE-2026-7045

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSp

6.3
CVE-2026-7044

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=cust

6.3
CVE-2026-7043

A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=

6.2
CVE-2018-25297

Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplyin

5.5
CVE-2018-25296

P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows

6.2
CVE-2018-25295

ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the applica

6.2
CVE-2018-25293

Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to

6.2
CVE-2018-25292

Bome Restorator 1793 contains a buffer overflow vulnerability that allows local attackers to crash the application by su

6.2
CVE-2018-25291

Project64 2.3.2 contains a buffer overflow vulnerability in the Plugin Directory settings field that allows local attack

6.2
CVE-2018-25290

Easyboot 6.6.0 contains a buffer overflow vulnerability in the Replace Text function that allows local attackers to cras

6.2
CVE-2018-25289

Softdisk 3.0.3 contains a buffer overflow vulnerability in the registration code dialog that allows local attackers to c

6.2
CVE-2018-25288

StyleWriter 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplyi

5.5
CVE-2018-25287

Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application b

6.2
CVE-2018-25286

Easy PhotoResQ 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supp

5.5
CVE-2018-25285

Fathom 2.4 contains a buffer overflow vulnerability in the Authorization Code field that allows local attackers to crash

6.2
CVE-2018-25284

HD Tune Pro 5.70 contains a buffer overflow vulnerability that allows local attackers to crash the application by supply

6.2
CVE-2018-25282

Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing

5.5
CVE-2018-25281

iCash 7.6.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying a

5.5
CVE-2018-25280

Infiltrator Network Security Scanner 4.6 contains a buffer overflow vulnerability that allows local attackers to crash t

6.2
CVE-2018-25279

jiNa OCR Image to Text 1.0 contains a denial of service vulnerability that allows local attackers to crash the applicati

6.2
CVE-2018-25278

PicaJet FX 2.6.5 contains a denial of service vulnerability that allows local attackers to crash the application by subm

6.2
CVE-2018-25277

PixGPS 1.1.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying

5.5
CVE-2018-25276

RoboImport 1.2.0.72 contains a denial of service vulnerability that allows local attackers to crash the application by s

6.2
CVE-2018-25275

Faleemi Plus 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supp

6.2
CVE-2018-25274

InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by im

6.2
CVE-2018-25273

CrossFont 7.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by submittin

6.2
CVE-2018-25264

TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to cra

4.7
CVE-2026-7028

A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of t

4.5
CVE-2026-7026

A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component

5.4
CVE-2026-7024

A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unk

6.3
CVE-2026-7023

A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function Execut

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started