Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 35/1777
6.2
CVE-2026-49307

Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability m

6.2
CVE-2026-49305

Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability

6.2
CVE-2026-49304

Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerabil

5.1
CVE-2026-49303

Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may a

6.2
CVE-2026-49302

Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerabili

6.2
CVE-2026-49301

Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect

6.3
CVE-2026-20000

A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function

6.3
CVE-2026-19999

A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is t

4.3
CVE-2026-19998

A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file

4.7
CVE-2026-19997

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the fil

4.3
CVE-2026-19996

A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin

6.3
CVE-2026-19994

A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the fil

4.3
CVE-2026-19993

A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality

4.3
CVE-2026-19988

A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of th

5.3
CVE-2026-19987

A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknow

5.3
CVE-2026-14832

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership che

5.9
CVE-2026-13700

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request a

5.4
CVE-2026-19986

A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the funct

6.3
CVE-2026-19984

A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the

5.3
CVE-2026-19978

A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted eleme

6.6
CVE-2026-19976

A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /

5.6
CVE-2026-19974

A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulnerability affects the

6.3
CVE-2026-19973

A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown f

6.3
CVE-2026-19972

A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the fi

4.7
CVE-2026-19971

A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of th

6.3
CVE-2026-19970

A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function Assimp::MDLImporter:

5.4
CVE-2026-19969

A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted element is the func

4.3
CVE-2026-19968

A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp:

6.3
CVE-2026-19967

A security flaw has been discovered in Open Asset Import Library Assimp 17c12da. Impacted is the function Assimp::Compre

5.4
CVE-2026-19966

A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown pro

5.5
CVE-2026-19964

A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/

6.3
CVE-2026-19958

A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of

6.3
CVE-2026-19957

A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/to

6.3
CVE-2026-19956

A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_

6.1
CVE-2026-74796

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attack

6.5
CVE-2026-74786

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString

6.5
CVE-2026-74785

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass exis

6.5
CVE-2026-73059

stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChann

5.8
CVE-2026-73058

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthe

6.5
CVE-2026-72888

Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_r

6.4
CVE-2026-2357

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcod

4.3
CVE-2026-18347

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa

6.5
CVE-2026-17608

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forg

4.9
CVE-2026-17604

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa

5.3
CVE-2026-12998

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D

6.5
CVE-2026-9767

The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'or

4.9
CVE-2026-2283

The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions u

6.3
CVE-2026-19934

A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the f

6.5
CVE-2026-19726

The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, all

6.1
CVE-2026-19712

The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started