Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 62/1777
6.5
CVE-2026-68078

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-68077

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-68075

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-67591

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-67555

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-67554

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-67553

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-66277

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-66276

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-66275

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-49004

The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi

4.3
CVE-2026-17515

The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio

5.3
CVE-2026-16981

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa

6.5
CVE-2026-16968

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users

5.4
CVE-2026-16942

The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand

4.3
CVE-2026-16613

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable

6.1
CVE-2026-16583

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8

6.1
CVE-2026-8790

The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST paramete

6.5
CVE-2026-7753

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing

6.7
CVE-2026-66839

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil

6.7
CVE-2026-66344

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerabi

4.9
CVE-2026-5062

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre

4.3
CVE-2026-18903

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so

6.5
CVE-2026-15941

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f

6.5
CVE-2026-11421

The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje

6.3
CVE-2026-18896

A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown fun

4.7
CVE-2026-18856

A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil

5.3
CVE-2026-45705

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin

5.3
CVE-2026-18853

A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu

4.9
CVE-2026-18103

A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program

4.3
CVE-2026-18819

A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul

6.3
CVE-2026-18818

A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView o

6.8
CVE-2026-70620

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke

6.7
CVE-2026-70594

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions

6.6
CVE-2026-70593

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff

5.5
CVE-2026-70592

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw

4.1
CVE-2026-70591

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin ima

4.8
CVE-2026-70590

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password

4.8
CVE-2026-70589

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede

6.1
CVE-2026-52370

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu

6.1
CVE-2026-51144

Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker

5.0
CVE-2026-18816

A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file

5.0
CVE-2026-70588

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin fail

6.5
CVE-2026-70493

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built

6.5
CVE-2026-70491

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap

6.3
CVE-2026-70490

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the termi

6.5
CVE-2026-70489

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio

4.3
CVE-2026-70488

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync

5.3
CVE-2026-70487

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di

6.3
CVE-2026-54020

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolv

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started