Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 399/1777
4.9
CVE-2025-12680

Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di

6.5
CVE-2025-12679

A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst

6.5
CVE-2025-47402

Transient DOS when processing a received frame with an excessively large authentication information element.

6.8
CVE-2025-47364

Memory corruption while calculating offset from partition start point.

6.8
CVE-2025-47363

Memory corruption when calculating oversized partition sizes without proper checks.

4.3
CVE-2025-15395

IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violatio

6.5
CVE-2022-50980

A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pre

6.5
CVE-2022-50979

An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pr

5.3
CVE-2026-1760

A flaw was found in SoupServer. This HTTP request smuggling vulnerability occurs because SoupServer improperly handles r

6.2
CVE-2026-1757

A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocat

5.7
CVE-2025-7105

A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork

5.3
CVE-2025-6208

The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption

6.5
CVE-2024-4147

In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p

6.5
CVE-2026-20422

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

6.5
CVE-2026-20421

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

6.5
CVE-2026-20420

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,

6.5
CVE-2026-20419

In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead

5.3
CVE-2026-20417

In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p

5.5
CVE-2026-20415

In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if

6.7
CVE-2026-20414

In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri

6.7
CVE-2026-20413

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of

6.7
CVE-2026-20410

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of

6.5
CVE-2026-20406

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if

6.5
CVE-2026-20405

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i

6.5
CVE-2026-20404

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

6.5
CVE-2026-20403

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i

6.5
CVE-2026-20402

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

5.4
CVE-2026-22881

Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attac

6.1
CVE-2026-20711

Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacke

4.3
CVE-2026-0658

The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, whi

6.3
CVE-2026-1746

A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/ap

4.3
CVE-2026-1745

A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. Th

4.7
CVE-2026-1742

A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncl

6.6
CVE-2026-1741

A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the f

5.3
CVE-2026-1739

A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the

5.3
CVE-2026-1738

A flaw has been found in Open5GS up to 2.7.6. The impacted element is the function sgwc_tunnel_add of the file /src/sgwc

5.3
CVE-2026-1737

A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function sgwc_s5c_handle_create_bearer_

5.3
CVE-2026-1736

A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_create_indir

4.3
CVE-2026-1735

A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the

5.3
CVE-2026-1734

A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file

4.3
CVE-2026-1733

A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /

6.4
CVE-2023-54343

QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to in

6.4
CVE-2022-50952

Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Nam

6.4
CVE-2022-50951

WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject

6.5
CVE-2022-50950

Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths w

5.4
CVE-2022-50942

Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malic

6.4
CVE-2022-50941

BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious

6.4
CVE-2022-50940

Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to i

6.4
CVE-2022-50797

Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote at

6.5
CVE-2021-47921

Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipula

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started