Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 31/1777
6.5
CVE-2026-49452

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-

6.5
CVE-2026-66781

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectiv

5.3
CVE-2026-55106

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source AP

6.1
CVE-2026-52606

A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitr

6.8
CVE-2026-50576

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic

4.0
CVE-2026-50126

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteo

6.5
CVE-2026-48744

Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in sale

6.1
CVE-2026-30250

Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90

5.5
CVE-2026-75485

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy o

5.5
CVE-2026-73834

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper

6.7
CVE-2026-71477

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/

4.3
CVE-2026-47245

MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate

5.3
CVE-2026-46482

### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing a

5.3
CVE-2026-45734

MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-

4.6
CVE-2026-45129

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate reque

5.3
CVE-2026-45125

MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names c

4.3
CVE-2026-45124

MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consis

4.3
CVE-2026-45123

MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6

4.3
CVE-2026-45122

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissio

4.3
CVE-2026-45121

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistentl

5.4
CVE-2026-45120

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status c

4.6
CVE-2026-45119

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate cer

6.3
CVE-2026-75032

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/

5.3
CVE-2026-74009

Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.

5.3
CVE-2026-74008

Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.

5.3
CVE-2026-74007

Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions

4.3
CVE-2026-74006

Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

5.4
CVE-2026-74004

Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions.

4.3
CVE-2026-74003

Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

5.4
CVE-2026-73995

Subscriber Broken Authentication in User Registration <= 5.2.6 versions.

4.6
CVE-2026-73426

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cro

6.5
CVE-2026-73404

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

6.5
CVE-2026-73399

Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

6.5
CVE-2026-73398

Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.

6.5
CVE-2026-73395

Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versi

4.9
CVE-2026-73383

Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.

6.5
CVE-2026-73379

Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.

6.5
CVE-2026-73359

Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.

6.5
CVE-2026-73352

Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.

6.5
CVE-2026-73348

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

4.3
CVE-2026-70657

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined

6.3
CVE-2026-68568

Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.

6.5
CVE-2026-68565

Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.

6.5
CVE-2026-66679

Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.

6.5
CVE-2026-66651

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.

6.5
CVE-2026-66646

Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.

6.5
CVE-2026-66645

Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.

6.5
CVE-2026-66644

Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.

6.5
CVE-2026-66643

Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.

6.5
CVE-2026-66641

Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started