Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 41/1777
6.5
CVE-2026-73559

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions Complet

5.3
CVE-2026-19487

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends

5.3
CVE-2026-73558

vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x *

5.3
CVE-2026-73556

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex paramet

5.3
CVE-2026-73555

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in

5.3
CVE-2026-73508

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.

6.1
CVE-2026-73506

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune

6.5
CVE-2026-70462

rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows

5.3
CVE-2026-70459

rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remot

6.5
CVE-2026-70457

rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is use

5.9
CVE-2026-53801

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows

4.7
CVE-2026-53800

rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows atta

6.3
CVE-2026-53799

rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply a

5.3
CVE-2026-53798

rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that al

4.7
CVE-2026-53797

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an

6.3
CVE-2026-53796

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon recei

5.3
CVE-2026-53794

rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-al

6.5
CVE-2026-53792

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a ma

6.5
CVE-2026-53789

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope o

6.5
CVE-2026-53788

rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allow

6.5
CVE-2026-53786

rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-leve

4.3
CVE-2026-49856

@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version

4.7
CVE-2026-49820

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo

4.7
CVE-2026-14256

ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstan

5.3
CVE-2026-73403

Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.

5.3
CVE-2026-73401

Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.

6.5
CVE-2026-73357

Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.

5.3
CVE-2026-73353

Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.

5.3
CVE-2026-73349

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

5.9
CVE-2026-73344

Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.

6.5
CVE-2026-73340

Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.

5.4
CVE-2026-67990

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager

6.5
CVE-2026-66693

Subscriber Broken Access Control in Motors <= 1.4.113 versions.

6.3
CVE-2026-66689

Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions.

6.5
CVE-2026-66687

Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.

6.5
CVE-2026-66660

Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.

6.0
CVE-2026-66654

Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.

6.5
CVE-2026-66471

Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.

6.5
CVE-2026-66467

Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.

6.5
CVE-2026-66464

Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.

6.5
CVE-2026-66460

Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.

6.5
CVE-2026-66459

Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.

6.5
CVE-2026-66456

Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.

6.0
CVE-2026-66455

Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.

6.5
CVE-2026-66454

Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.

6.5
CVE-2026-66444

Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.

6.5
CVE-2026-61978

Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.

6.5
CVE-2026-28182

Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.

6.5
CVE-2026-28181

Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.

6.5
CVE-2026-28174

Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started