Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 69/1777
5.4
CVE-2026-17350

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce

6.5
CVE-2026-17348

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef

5.8
CVE-2026-10686

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing

4.3
CVE-2025-62347

HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and

4.3
CVE-2026-67350

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to re

5.3
CVE-2026-28145

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User

4.3
CVE-2026-28144

Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti

5.3
CVE-2026-64607

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma

6.5
CVE-2026-44615

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi

5.3
CVE-2026-17567

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne

5.3
CVE-2026-18437

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access

5.3
CVE-2026-18436

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the

5.3
CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi

4.2
CVE-2026-18218

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attemp

6.8
CVE-2026-18215

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization

6.8
CVE-2026-18214

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor

4.2
CVE-2026-18211

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo

6.5
CVE-2026-18208

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source

6.5
CVE-2026-18203

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr

4.9
CVE-2026-16105

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin

5.4
CVE-2026-8155

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints

6.5
CVE-2026-15209

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a

6.5
CVE-2026-14931

The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation

4.3
CVE-2026-14929

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo

6.5
CVE-2026-14928

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp

6.1
CVE-2026-14922

WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 throug

6.1
CVE-2026-14921

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_

4.3
CVE-2026-14847

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i

6.1
CVE-2026-14845

The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor re

5.3
CVE-2026-14843

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target

6.5
CVE-2026-14834

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX

6.8
CVE-2026-14833

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend

6.5
CVE-2026-14554

The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them

5.3
CVE-2026-14317

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t

5.4
CVE-2026-12697

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us

4.3
CVE-2026-12376

The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing

4.8
CVE-2026-63220

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For

6.3
CVE-2026-62323

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the se

4.3
CVE-2026-55499

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri

6.5
CVE-2026-55497

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image

4.3
CVE-2026-55496

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi

4.3
CVE-2026-55495

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W

5.3
CVE-2026-43833

Full details and mitigation steps are currently restricted and will be published at a later date.

6.1
CVE-2026-14540

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-t

6.5
CVE-2026-66720

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy

6.5
CVE-2026-66369

The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-

6.5
CVE-2026-66364

The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu

6.5
CVE-2026-66349

The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed

6.5
CVE-2026-65421

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v

6.5
CVE-2026-63550

The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started