Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 52/1777
6.5
CVE-2026-68872

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team

6.5
CVE-2026-68871

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id

5.3
CVE-2026-68870

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va

6.5
CVE-2026-72900

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

6.5
CVE-2026-72739

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs

4.3
CVE-2026-72732

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp

6.5
CVE-2026-70622

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t

6.3
CVE-2026-72728

Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed

6.3
CVE-2026-71577

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed

5.5
CVE-2026-63623

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were tempora

5.4
CVE-2026-56619

HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out

4.3
CVE-2026-12624

Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra

6.5
CVE-2026-72726

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u

5.4
CVE-2026-72725

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo

4.3
CVE-2026-72724

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c

5.3
CVE-2026-72723

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano

4.3
CVE-2026-72722

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_

5.3
CVE-2026-72721

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec

6.4
CVE-2026-72720

Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse

6.7
CVE-2026-72719

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf

4.3
CVE-2026-56620

HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor

5.8
CVE-2026-71959

Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c

5.4
CVE-2026-63105

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome

6.7
CVE-2026-16742

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed

4.7
CVE-2026-15060

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o

5.5
CVE-2026-15059

Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver

6.5
CVE-2026-6373

Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow

6.8
CVE-2026-19278

A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configu

5.5
CVE-2026-59088

A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI im

5.3
CVE-2026-72588

A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d

6.1
CVE-2026-72587

A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison

5.4
CVE-2026-72583

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us

5.4
CVE-2026-72576

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho

6.1
CVE-2026-72574

A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control

5.4
CVE-2026-72570

A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec

5.4
CVE-2026-66642

Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP

6.5
CVE-2026-65945

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,

6.5
CVE-2026-19404

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati

5.3
CVE-2026-66411

DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut

4.8
CVE-2026-66410

Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or alt

5.3
CVE-2026-66409

DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma

4.6
CVE-2026-66408

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec

4.8
CVE-2026-66406

DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle at

6.5
CVE-2026-66404

DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activi

6.5
CVE-2026-21083

Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

5.5
CVE-2026-21082

Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

6.5
CVE-2026-21080

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access

6.5
CVE-2026-21079

Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept tr

6.5
CVE-2026-21078

Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows ad

5.5
CVE-2026-21077

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started