Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

126,669
Total
101
Known Exploited
Showing 88,803 of 126,669 total · Page 3/1777
6.8
CVE-2026-82262

Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that

6.8
CVE-2026-82020

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can in

6.5
CVE-2026-77939

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attack

4.9
CVE-2026-77218

PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-b

4.9
CVE-2026-77217

PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer derefere

5.2
CVE-2026-77184

In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comme

6.3
CVE-2026-76798

The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its genera

6.3
CVE-2026-76797

The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutr

4.6
CVE-2026-76794

MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML.

4.9
CVE-2026-75126

PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities

4.9
CVE-2026-75125

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /c

5.4
CVE-2026-70331

Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to per

5.4
CVE-2026-70309

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature

4.3
CVE-2026-66798

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

6.5
CVE-2026-66324

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoo

5.4
CVE-2026-66323

Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attac

5.4
CVE-2026-62904

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

4.4
CVE-2026-58616

Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft E

4.3
CVE-2026-55834

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0,

6.6
CVE-2026-55569

aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the hand

4.3
CVE-2026-55566

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext

6.5
CVE-2026-55549

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from

4.3
CVE-2026-55547

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from

6.5
CVE-2026-55545

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce

5.0
CVE-2026-55425

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity

5.0
CVE-2026-55067

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v

4.3
CVE-2026-55064

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin

6.4
CVE-2026-54746

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0

6.1
CVE-2026-82330

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed)

6.1
CVE-2026-82328

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not

5.5
CVE-2026-82327

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper t

6.1
CVE-2026-82324

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the

5.3
CVE-2026-82220

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

5.5
CVE-2026-82181

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote

4.3
CVE-2026-81761

Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.

5.4
CVE-2026-81759

Contributor Broken Access Control in WpEvently <= 5.5.0 versions.

6.5
CVE-2026-81341

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer

4.3
CVE-2026-81299

Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.

4.3
CVE-2026-81284

Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.

6.1
CVE-2026-5953

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics

6.1
CVE-2026-5800

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software I

5.3
CVE-2026-5096

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including

5.4
CVE-2026-4378

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Sof

6.4
CVE-2026-3423

The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' confi

5.4
CVE-2026-38725

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript v

6.1
CVE-2026-37710

Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site na

5.3
CVE-2026-15603

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes l

4.3
CVE-2026-82257

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fi

5.3
CVE-2026-82256

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the N

6.8
CVE-2026-82255

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where cr

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 126,669 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started