Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 44/1777
6.3
CVE-2026-17420

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

6.5
CVE-2026-17419

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutraliza

6.8
CVE-2026-17268

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

6.5
CVE-2026-17266

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper

4.3
CVE-2026-17222

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to imp

4.3
CVE-2026-17109

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to add unexpected parameters to a command due t

5.4
CVE-2026-73295

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearc

6.5
CVE-2026-73239

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.

6.1
CVE-2026-73238

XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme

6.1
CVE-2026-73237

XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1.

5.4
CVE-2026-48552

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js

6.1
CVE-2026-48550

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via

4.3
CVE-2026-18144

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

4.3
CVE-2026-18106

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper

4.3
CVE-2026-17094

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate

6.4
CVE-2026-16694

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated us

4.3
CVE-2026-70547

An authenticated user without repository read permission may access package metadata under specific conditions.

5.9
CVE-2026-69107

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

6.5
CVE-2026-68971

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check

6.5
CVE-2026-68970

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that

6.5
CVE-2026-68969

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit

6.5
CVE-2026-68758

A low-privileged authenticated user may access restricted support information under specific conditions.

5.4
CVE-2026-68076

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'

5.3
CVE-2026-66384 KEV

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

6.7
CVE-2026-66016

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessi

6.8
CVE-2026-65940

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible l

6.8
CVE-2026-65939

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arb

4.3
CVE-2026-65938

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API

6.5
CVE-2026-65017

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a

6.5
CVE-2026-59244

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates

5.4
CVE-2026-59242

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th

4.3
CVE-2026-54183

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas

5.5
CVE-2026-19548

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker

5.3
CVE-2026-73290

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions req

5.4
CVE-2026-73287

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriv

6.5
CVE-2026-73265

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co

5.4
CVE-2026-73262

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.

5.3
CVE-2026-68760

An unauthenticated user may bypass authentication under specific cache conditions.

6.6
CVE-2026-68756

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

4.3
CVE-2026-68755

A bundle writer may create misleading release promotion information under specific conditions.

6.5
CVE-2026-68754

A repository publisher without delete permission may modify protected package content under specific conditions.

5.3
CVE-2026-68753

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in

4.3
CVE-2026-66382

An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

5.3
CVE-2026-66381

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co

4.3
CVE-2026-66380

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi

4.3
CVE-2026-66379

An authenticated user may view private Puppet module metadata without repository read access.

4.3
CVE-2026-66378

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

5.3
CVE-2026-66377

An unauthenticated user may access restricted repository information under specific conditions.

4.2
CVE-2026-66376

Credentials for a deleted user may remain valid for a short period under specific conditions.

6.8
CVE-2026-49349

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started