Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 56/1777
5.3
CVE-2026-19206

A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopT

6.5
CVE-2026-16637

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis

6.5
CVE-2026-56794

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo

6.5
CVE-2026-49008

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity

6.2
CVE-2026-18938

A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a

5.3
CVE-2026-49006

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss

4.4
CVE-2026-19079

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W

5.4
CVE-2026-16027

Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ

5.3
CVE-2026-15239

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache

5.9
CVE-2026-15211

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal

5.3
CVE-2026-15148

The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates fro

5.3
CVE-2026-12261

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin

6.5
CVE-2026-16265

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r

6.5
CVE-2026-16039

The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders,

5.4
CVE-2026-15386

The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att

6.5
CVE-2026-15359

The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow

5.4
CVE-2026-15245

The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con

4.3
CVE-2026-15214

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription

6.1
CVE-2026-15032

The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an

6.1
CVE-2026-14331

The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a

6.4
CVE-2026-12801

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid

6.5
CVE-2026-11907

The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This

5.5
CVE-2026-45204

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kern

4.3
CVE-2026-17264

Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of

5.5
CVE-2026-7405

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-B

4.1
CVE-2026-71555

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS do

5.3
CVE-2026-71554

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header

5.1
CVE-2026-71498

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final byt

4.7
CVE-2026-71497

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl

6.1
CVE-2026-71478

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the Attributes

6.1
CVE-2026-71435

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automag

5.3
CVE-2026-71434

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms

5.3
CVE-2026-71433

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin

6.2
CVE-2026-71430

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function

5.5
CVE-2026-70639

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper w

6.5
CVE-2026-70633

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres

5.5
CVE-2026-70631

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in

5.5
CVE-2026-70630

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na

5.5
CVE-2026-70629

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na

6.5
CVE-2026-70557

diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of

4.3
CVE-2026-64664

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont

6.5
CVE-2026-64663

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup

6.5
CVE-2026-64662

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont

5.3
CVE-2026-61632

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2

6.8
CVE-2026-5336

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren

5.4
CVE-2026-54717

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable

6.5
CVE-2026-48083

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.3
CVE-2026-48078

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.3
CVE-2026-48077

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

6.5
CVE-2026-48076

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started