Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 6/1777
6.8
CVE-2026-81095

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServ

6.8
CVE-2026-81092

mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in serv

4.0
CVE-2026-80213

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length

5.9
CVE-2026-80211

FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_

6.5
CVE-2026-80210

FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the

4.3
CVE-2026-80209

The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes

5.3
CVE-2026-80207

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. Reso

4.4
CVE-2026-75573

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is suppl

5.9
CVE-2026-75159

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication m

5.4
CVE-2026-71402

An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capt

6.1
CVE-2026-5738

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatic

4.3
CVE-2026-59280

Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a control

6.8
CVE-2026-59272

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is expose

6.5
CVE-2026-40526

Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read a

6.1
CVE-2026-19854

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connecti

5.3
CVE-2026-11754

Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: thr

6.1
CVE-2026-11747

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syW

6.4
CVE-2025-62342

HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of

5.4
CVE-2026-81668

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the paren

6.5
CVE-2026-81658

A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving

5.3
CVE-2026-81562

A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the fi

5.3
CVE-2026-81560

A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of t

4.3
CVE-2026-5218

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Techno

6.5
CVE-2026-17562

Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Fu

5.4
CVE-2026-81279

Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.

5.3
CVE-2026-81276

Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.

5.3
CVE-2026-81274

Subscriber Broken Access Control in Ditty <= 3.1.67 versions.

4.9
CVE-2026-81272

Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.

6.8
CVE-2026-78275

Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.

6.5
CVE-2026-78273

Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.

6.1
CVE-2026-59355

In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validat

4.3
CVE-2026-78139

The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one

4.3
CVE-2026-78138

The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sal

5.3
CVE-2026-78125

The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in a

5.9
CVE-2026-76549

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its bac

6.5
CVE-2026-59278

JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these m

6.6
CVE-2026-59275

A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — fu

6.5
CVE-2026-59274

The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an at

5.3
CVE-2026-59271

When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown

4.9
CVE-2026-47894

Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configure

6.1
CVE-2026-47887

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a con

6.1
CVE-2026-47883

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue ap

5.9
CVE-2026-47881

Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for examp

5.4
CVE-2026-47880

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String

5.6
CVE-2026-47878

DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes di

5.6
CVE-2026-47875

Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deser

6.4
CVE-2026-47864

SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and

4.4
CVE-2026-19454

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup

6.6
CVE-2026-19225

The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators,

4.3
CVE-2026-16569

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started