Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 55/1777
6.5
CVE-2026-16562

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics

6.8
CVE-2026-16559

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur

5.4
CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it

6.1
CVE-2026-16535

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r

5.3
CVE-2026-16282

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t

4.8
CVE-2026-16269

The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica

6.4
CVE-2026-18988

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a

5.9
CVE-2026-49343

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie

6.5
CVE-2026-47127

Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR

5.7
CVE-2026-64676

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In

5.3
CVE-2026-46405

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth m

6.6
CVE-2026-11743

The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o

4.0
CVE-2026-71381

Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could r

5.3
CVE-2026-69207

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in COR

4.3
CVE-2026-59717

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr

5.3
CVE-2026-54338

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid in

6.3
CVE-2026-19246

A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the f

4.7
CVE-2026-19244

A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of t

4.4
CVE-2026-11425

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo

5.5
CVE-2026-66151

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the

5.0
CVE-2026-62293

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11

6.3
CVE-2026-19243

A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_comman

5.3
CVE-2026-19113

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of servic

6.8
CVE-2026-19017

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read whe

4.2
CVE-2026-19016

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission

5.3
CVE-2026-19015

Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumptio

4.3
CVE-2026-19014

Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumpti

5.3
CVE-2026-19012

Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service

4.2
CVE-2026-15970

Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypa

4.8
CVE-2026-71850

Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from

5.3
CVE-2026-71848

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the langua

6.5
CVE-2026-70561

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,

5.3
CVE-2025-71413

Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w

5.3
CVE-2025-71411

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c

5.3
CVE-2025-71410

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and

6.5
CVE-2026-56818

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the Redis

6.5
CVE-2026-47364

In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datado

6.3
CVE-2026-47363

In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts a

4.6
CVE-2026-47362

In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive con

6.4
CVE-2026-47361

In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission gu

5.5
CVE-2026-44965

In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWid

6.5
CVE-2026-44964

In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with

5.3
CVE-2026-19229

A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functiona

4.3
CVE-2026-19213

A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCo

6.3
CVE-2026-71557

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference name

5.3
CVE-2026-66062

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the c

4.3
CVE-2026-19212

A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WT

6.5
CVE-2026-48093

The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex

6.3
CVE-2026-19210

A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of

5.9
CVE-2026-37171

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started