Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 38/1777
6.5
CVE-2026-58224

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of rec

5.3
CVE-2026-19879

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method p

6.3
CVE-2026-53472

A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an

5.3
CVE-2026-1621

Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of

5.3
CVE-2026-19830

A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of th

4.3
CVE-2026-19829

A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code

6.3
CVE-2026-19828

A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file Pla

5.3
CVE-2026-19827

A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin

5.8
CVE-2026-73630

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoin

5.8
CVE-2026-73049

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint

5.8
CVE-2026-73048

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoin

6.5
CVE-2026-72838

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoin

6.8
CVE-2026-72835

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated u

4.3
CVE-2026-72834

filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch

5.4
CVE-2026-72832

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss()

5.4
CVE-2026-72823

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its

5.4
CVE-2026-72821

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field op

4.9
CVE-2026-72820

Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directori

6.5
CVE-2026-72817

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves th

6.5
CVE-2026-72816

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The real

6.5
CVE-2026-72812

SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint tha

5.5
CVE-2026-19617

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration

6.5
CVE-2026-16810

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v

5.9
CVE-2026-16739

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request

6.8
CVE-2026-14290

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputti

4.9
CVE-2026-12743

The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-base

4.3
CVE-2025-10308

The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc

4.7
CVE-2026-19787

A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the

4.3
CVE-2026-19786

A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the fi

6.3
CVE-2026-19785

A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of th

4.3
CVE-2026-19784

A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Disciplin

5.3
CVE-2026-19770

A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadR

6.3
CVE-2026-19767

A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processin

6.3
CVE-2026-19765

A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vuln

4.7
CVE-2026-19761

A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the

6.3
CVE-2026-19756

A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjec

5.3
CVE-2026-73840

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST

4.2
CVE-2026-73657

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4,

4.3
CVE-2026-73489

Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service

5.0
CVE-2026-73479

dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attac

4.6
CVE-2026-73428

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to sto

4.9
CVE-2026-73304

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id

5.4
CVE-2026-73039

streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated

5.9
CVE-2026-56860

Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer

6.1
CVE-2026-56858

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitr

6.3
CVE-2026-19752

A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affect

6.3
CVE-2026-19751

A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected el

5.0
CVE-2026-73480

gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers

4.8
CVE-2026-18741

Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management mod

6.5
CVE-2026-18715

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started