Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 40/1777
6.5
CVE-2026-72631

Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC

4.3
CVE-2026-49096

Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malf

6.5
CVE-2026-49089

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All

4.3
CVE-2026-19746

A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file tracer

4.3
CVE-2026-19745

A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave

5.3
CVE-2026-16929

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer

5.4
CVE-2026-16878

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-o

4.3
CVE-2026-16871

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap b

5.3
CVE-2026-16861

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

5.3
CVE-2026-16859

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

6.5
CVE-2026-16853

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

4.3
CVE-2026-16713

IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive inform

6.5
CVE-2026-16692

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-bas

5.7
CVE-2026-10571

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecu

5.7
CVE-2026-73651

TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Ora

5.4
CVE-2026-73481

phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / b

6.1
CVE-2026-73038

NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to esca

6.1
CVE-2026-73037

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter

5.6
CVE-2026-73647

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend

5.3
CVE-2026-73565

@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request t

4.7
CVE-2026-73563

Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registra

6.5
CVE-2026-73562

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.

4.9
CVE-2026-67613

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitra

4.2
CVE-2026-19730

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TR

6.5
CVE-2026-12236

The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By

4.3
CVE-2026-59763

Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

4.3
CVE-2026-58510

GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on pu

5.3
CVE-2026-58507

Private Repository Existence Disclosure via go-get Meta Endpoint

4.3
CVE-2026-58444

Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private rep

6.5
CVE-2026-58442

Repository migration SSRF via multi-answer DNS allow-list bypass

6.3
CVE-2026-58441

SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

6.8
CVE-2026-58440

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of pr

5.4
CVE-2026-58435

Gitea LFS Deploy-Key Privilege Escalation

5.9
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti

4.3
CVE-2026-58431

Public-only API token restriction is not enforced on team API routes

4.9
CVE-2026-58429

Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

6.5
CVE-2026-58428

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

4.3
CVE-2026-58425

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

4.4
CVE-2026-58420

Local File Inclusion via file:// URI in Migration Restore

6.5
CVE-2026-57897

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

5.9
CVE-2026-57886

Cross-repository issue/comment attachment re-linking can expose private attachment content

6.2
CVE-2026-56755

Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

6.2
CVE-2026-56657

Gitea SSH Key Parser Denial of Service

5.4
CVE-2026-55986

Email Management API Bypasses ManageCredentials Feature Restrictions

4.3
CVE-2026-50105

RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

6.5
CVE-2026-42931

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

6.5
CVE-2026-24059

The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creat

6.1
CVE-2026-73671

Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in clas

6.3
CVE-2026-73576

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice i

6.1
CVE-2026-73572

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started