Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 5/1777
4.6
CVE-2026-73839

Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the r

5.4
CVE-2026-71396

Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.

6.5
CVE-2026-68967

Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that

5.3
CVE-2026-54084

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

4.7
CVE-2026-81893

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an e

6.3
CVE-2026-81834

A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminal

5.5
CVE-2026-81833

A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function

5.4
CVE-2026-81731

Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description

6.5
CVE-2026-81729

Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs

5.6
CVE-2026-81530

A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management

5.4
CVE-2026-81528

A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write pat

6.5
CVE-2026-81527

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver

6.5
CVE-2026-81526

The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding i

5.4
CVE-2026-81524

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to

4.4
CVE-2026-81523

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied

6.5
CVE-2026-81521

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserv

6.3
CVE-2026-59322

The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When de

4.2
CVE-2026-59321

A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report T

6.5
CVE-2026-59320

When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing th

4.3
CVE-2026-59319

RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values w

6.5
CVE-2026-59317

DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and

5.3
CVE-2026-59315

The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config

6.8
CVE-2026-59311

A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choos

5.9
CVE-2026-59294

ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without strippin

6.6
CVE-2026-59293

Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks m

6.1
CVE-2026-59281

Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then rende

5.9
CVE-2026-59276

Several components in Spring Security compare security-sensitive values using standard string equality (String.equals())

6.5
CVE-2026-54732

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js u

5.3
CVE-2026-37067

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauth

5.5
CVE-2026-34620

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to applicat

5.5
CVE-2026-34616

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory ex

6.0
CVE-2026-25250

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot

4.9
CVE-2026-18374

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the

5.3
CVE-2026-81724

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau

6.2
CVE-2026-81720

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing

5.2
CVE-2026-81716

openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_pat

6.8
CVE-2026-81706

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,

5.5
CVE-2026-81703

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m

5.5
CVE-2026-81697

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution fla

5.5
CVE-2026-81687

openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specifi

6.2
CVE-2026-81686

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set m

6.2
CVE-2026-81684

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to

6.2
CVE-2026-81682

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes

4.6
CVE-2026-81681

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB

4.0
CVE-2026-81680

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, al

5.3
CVE-2026-81664

The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each admi

6.1
CVE-2026-81334

darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's

6.5
CVE-2026-81101

The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute i

6.8
CVE-2026-81100

tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src

6.8
CVE-2026-81099

tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/htt

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started