Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 32/1777
6.5
CVE-2026-66640

Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.

6.5
CVE-2026-66639

Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.

6.5
CVE-2026-66638

Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.

6.5
CVE-2026-66637

Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.

6.5
CVE-2026-66636

Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.

4.3
CVE-2026-66634

Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

6.5
CVE-2026-59949

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate t

5.9
CVE-2026-50139

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit

6.0
CVE-2026-32467

Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.

6.8
CVE-2026-74984

Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thund

6.5
CVE-2026-74980

Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

6.5
CVE-2026-74976

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140

5.4
CVE-2026-74975

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

5.4
CVE-2026-74974

Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR

4.2
CVE-2026-74973

Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.3

4.3
CVE-2026-74972

Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ES

4.3
CVE-2026-74971

Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Fi

5.4
CVE-2026-74970

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb

5.4
CVE-2026-74968

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.

5.4
CVE-2026-74967

Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox E

5.4
CVE-2026-74963

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR

6.5
CVE-2026-74951

Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.

6.5
CVE-2026-74948

Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firef

6.5
CVE-2026-74945

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

5.3
CVE-2026-16309

Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessi

4.2
CVE-2026-75850

ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP hand

6.3
CVE-2026-75845

ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP serv

4.3
CVE-2026-75841

ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticat

4.3
CVE-2026-75839

ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object reference (IDOR) vulnerabil

4.3
CVE-2026-75835

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuth

5.4
CVE-2026-75834

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/sr

4.2
CVE-2026-75833

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contai

4.3
CVE-2026-75832

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a

5.4
CVE-2026-75107

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, secti

4.6
CVE-2026-74908

Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exac

5.9
CVE-2026-74907

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string

4.3
CVE-2026-74903

SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpoint, which

5.7
CVE-2026-5224

Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade I

5.3
CVE-2026-19608

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained a

5.4
CVE-2026-19447

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informat

6.3
CVE-2024-14046

A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController

6.3
CVE-2024-14045

A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/

4.3
CVE-2026-75151

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vu

4.3
CVE-2026-75093

A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_al

4.3
CVE-2026-75090

A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_ggu

6.3
CVE-2026-75088

A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the f

6.3
CVE-2026-75087

A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /

6.3
CVE-2026-75086

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi

4.3
CVE-2026-75082

A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/r

4.3
CVE-2026-75081

A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/accoun

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started