Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 50/1777
6.5
CVE-2026-20747

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni

5.9
CVE-2026-73068

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI

5.9
CVE-2026-6727

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a

4.3
CVE-2026-56720

CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that

6.5
CVE-2026-53414

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic

4.3
CVE-2026-19078

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the

6.5
CVE-2026-18638

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces

5.3
CVE-2026-14180

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han

6.1
CVE-2026-72925

SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi

6.8
CVE-2026-18636

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr

6.2
CVE-2026-17535

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by

4.3
CVE-2026-72785

Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only

5.4
CVE-2026-72784

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne

6.2
CVE-2026-72783

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne

6.5
CVE-2026-72782

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre

6.5
CVE-2026-72780

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey

4.5
CVE-2026-72779

Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create()

6.5
CVE-2026-72771

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when

6.2
CVE-2026-72744

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the

6.0
CVE-2026-69108

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is v

4.3
CVE-2026-59693

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.

6.8
CVE-2026-57263

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affec

6.8
CVE-2026-57262

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded

4.3
CVE-2026-72610

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

6.5
CVE-2026-72608

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

6.5
CVE-2026-72604

A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete ar

6.5
CVE-2026-72598

A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the se

6.5
CVE-2026-72597

A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with

6.5
CVE-2026-72560

A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTI

5.4
CVE-2026-72559

A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent

6.5
CVE-2026-72554

A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer

5.4
CVE-2026-72553

A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten

5.3
CVE-2026-72549

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers

5.4
CVE-2026-72542

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write

6.5
CVE-2026-72541

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe

6.5
CVE-2026-72539

An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem

6.0
CVE-2026-33922

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to in

5.2
CVE-2026-33921

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver

5.3
CVE-2026-71218

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function,

4.3
CVE-2026-19519

A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked

6.5
CVE-2026-19518

Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu

6.5
CVE-2026-19517

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit

6.5
CVE-2026-19391

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the

5.3
CVE-2026-8158

The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to

5.1
CVE-2026-6505

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv

5.9
CVE-2026-6181

The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after

5.7
CVE-2026-5304

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil

5.7
CVE-2026-5303

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv

4.1
CVE-2026-18348

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst

4.3
CVE-2026-14549

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started