Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 42/1777
6.5
CVE-2026-28159

Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.

6.5
CVE-2026-28155

Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.

6.5
CVE-2026-27999

Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.

6.5
CVE-2026-27537

Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.

4.3
CVE-2026-21832

HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. I

5.6
CVE-2025-62314

HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or s

6.3
CVE-2026-73585

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a loca

6.3
CVE-2026-73584

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance

6.6
CVE-2026-73583

A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnera

4.3
CVE-2026-6470

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and

4.3
CVE-2026-18024

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific

4.2
CVE-2026-14681

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_

4.3
CVE-2026-14678

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a tab

5.3
CVE-2026-14672

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence

4.2
CVE-2026-14666

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query

6.5
CVE-2026-14663

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of

4.7
CVE-2025-52640

HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi

6.1
CVE-2026-73628

Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-UR

5.4
CVE-2026-73621

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor

6.5
CVE-2026-73619

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file an

6.5
CVE-2026-73616

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete

6.8
CVE-2026-73611

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configure

5.8
CVE-2026-73610

SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the admin

5.8
CVE-2026-73609

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that ret

5.8
CVE-2026-73607

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endp

5.8
CVE-2026-73606

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that

5.8
CVE-2026-73605

SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anony

6.5
CVE-2026-73604

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoi

5.3
CVE-2026-59502

: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

6.6
CVE-2026-19696

Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows

4.7
CVE-2026-19695

Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service

4.7
CVE-2026-19694

TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service

5.4
CVE-2026-14332

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or non

6.5
CVE-2026-14298

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit res

6.4
CVE-2026-3639

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `pp

4.7
CVE-2026-18622

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations

5.3
CVE-2026-3835

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protect

5.4
CVE-2026-19088

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentica

5.3
CVE-2026-13328

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-statu

5.4
CVE-2026-72506

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly spec

4.3
CVE-2026-19182

An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authen

5.4
CVE-2026-19135

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authentic

6.5
CVE-2026-18728

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4

6.3
CVE-2026-50544

NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a laten

6.1
CVE-2026-17431

PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and

6.8
CVE-2026-71194

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOT

4.2
CVE-2026-7366

IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower G

6.5
CVE-2026-71846

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secr

5.3
CVE-2026-18750

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_functi

6.5
CVE-2026-18744

Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying th

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started