Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 54/1777
4.7
CVE-2026-19359

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function

6.3
CVE-2026-19358

A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultF

5.3
CVE-2026-19357

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form

5.3
CVE-2026-19356

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/dat

6.3
CVE-2026-19354

A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an u

5.0
CVE-2026-19353

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the fi

6.3
CVE-2026-19350

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/in

6.3
CVE-2026-19347

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processin

6.5
CVE-2026-19345

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up

6.3
CVE-2026-19340

A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file bac

6.3
CVE-2026-19339

A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is th

5.3
CVE-2026-19338

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processG

5.3
CVE-2026-19337

A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/

5.3
CVE-2026-19336

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.crea

5.3
CVE-2026-19335

A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function

6.5
CVE-2026-18603

The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or

6.5
CVE-2026-18465

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a

6.5
CVE-2026-18037

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it

5.3
CVE-2026-17014

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its

6.5
CVE-2026-16992

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it

4.3
CVE-2026-16965

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a

6.1
CVE-2026-16032

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated an

5.3
CVE-2026-19334

A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown pa

5.3
CVE-2026-19333

A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a

5.3
CVE-2026-19332

A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functi

5.3
CVE-2026-19331

A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanva

5.3
CVE-2026-19330

A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_s

5.3
CVE-2026-19329

A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element i

5.3
CVE-2026-19328

A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/insta

5.3
CVE-2026-19327

A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession

4.4
CVE-2026-19326

A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the

5.3
CVE-2026-19325

A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35a

5.3
CVE-2026-19323

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected

5.3
CVE-2026-19288

A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This

5.3
CVE-2026-19287

A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the com

5.3
CVE-2026-19285

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vu

5.3
CVE-2026-19284

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProje

5.3
CVE-2026-19282

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts

5.3
CVE-2026-19281

A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generate

5.3
CVE-2026-19279

A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the fi

5.3
CVE-2026-19270

A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_jo

6.3
CVE-2026-19268

A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts t

5.5
CVE-2026-19266

A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the f

5.3
CVE-2026-19259

A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping

5.0
CVE-2026-16955

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwardi

4.8
CVE-2026-16953

The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti

5.3
CVE-2026-16608

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging

6.5
CVE-2026-16595

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti

6.5
CVE-2026-16590

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti

5.4
CVE-2026-16574

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started