Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 45/1777
4.4
CVE-2026-47234

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se

6.5
CVE-2026-47233

Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `

5.5
CVE-2026-14479

A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation

4.6
CVE-2025-59320

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s

4.3
CVE-2026-47232

Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modu

6.5
CVE-2026-47230

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re

5.4
CVE-2026-47229

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm

5.2
CVE-2026-47228

Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random pa

6.5
CVE-2026-47227

Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (

6.3
CVE-2026-16999

Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows S

5.3
CVE-2026-71408

A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.

5.6
CVE-2026-71407

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an

5.3
CVE-2026-70466

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.

6.5
CVE-2026-47226

Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload

5.4
CVE-2026-70560

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri

5.3
CVE-2026-17008

The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status i

5.3
CVE-2026-16990

The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-si

6.5
CVE-2026-16747

The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes

5.3
CVE-2026-16621

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succee

5.3
CVE-2026-15213

The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-

6.5
CVE-2026-15045

The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against

6.5
CVE-2026-68868

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re

6.1
CVE-2026-64955

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CS

6.5
CVE-2026-64952

The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLL

5.9
CVE-2026-18663

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess

6.5
CVE-2026-18652

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within

4.3
CVE-2025-41771

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl

5.4
CVE-2026-19217

The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM

5.3
CVE-2026-19073

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o

4.3
CVE-2026-19052

The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac

6.4
CVE-2026-19050

The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca

4.3
CVE-2026-18962

The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int

6.5
CVE-2026-18943

The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow

4.3
CVE-2026-18046

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability

5.3
CVE-2026-18035

The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo

6.1
CVE-2026-17013

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it

5.3
CVE-2026-16737

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca

5.4
CVE-2026-16066

The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it

4.3
CVE-2026-15388

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability

5.4
CVE-2026-15249

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i

4.3
CVE-2026-14859

The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a

4.3
CVE-2026-14858

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi

4.3
CVE-2026-14857

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his

4.3
CVE-2026-13612

The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al

4.3
CVE-2026-13177

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user

6.5
CVE-2026-13168

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users

6.5
CVE-2026-12976

The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a

6.3
CVE-2026-12235

The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (p

5.9
CVE-2026-12233

The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre

6.1
CVE-2026-12232

The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a cal

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started