Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 7/1777
4.3
CVE-2026-16568

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe

5.3
CVE-2026-16567

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token

4.8
CVE-2026-13414

The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a

5.3
CVE-2026-81486

A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_conte

5.3
CVE-2026-81485

A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the

5.3
CVE-2026-47874

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor N

5.9
CVE-2026-47863

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a

5.4
CVE-2026-47862

An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default

6.3
CVE-2026-47861

An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can caus

6.5
CVE-2026-47860

An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the c

5.4
CVE-2026-47859

RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frame

5.9
CVE-2026-47857

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a

6.3
CVE-2026-47856

Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type,

4.3
CVE-2026-47850

Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP

5.3
CVE-2026-47845

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is

5.5
CVE-2026-80158

A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter

4.1
CVE-2026-21808

HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of se

4.6
CVE-2026-75331

tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints i

5.4
CVE-2026-45694

LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnera

4.4
CVE-2026-21810

HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w

5.3
CVE-2026-77507

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

6.5
CVE-2026-62326

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

4.3
CVE-2026-62249

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

4.4
CVE-2026-61790

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

4.3
CVE-2026-55227

Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally s

6.1
CVE-2026-39275

Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code

5.8
CVE-2026-79939

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerabilit

4.3
CVE-2026-75601

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instan

5.9
CVE-2026-74774

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthe

6.5
CVE-2026-74771

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerab

4.3
CVE-2026-71172

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low

6.5
CVE-2026-71054

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily

5.3
CVE-2026-67275

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerabi

6.5
CVE-2026-49809

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used i

6.1
CVE-2026-47848

In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client

5.3
CVE-2026-47844

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for

6.5
CVE-2026-47842

Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as th

4.8
CVE-2026-47834

Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted

6.5
CVE-2026-46371

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple M

6.5
CVE-2026-46370

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels

5.9
CVE-2026-79940

Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Con

6.5
CVE-2026-75466

libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexe

4.9
CVE-2026-63179

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, au

6.5
CVE-2026-48786

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endp

4.3
CVE-2026-41262

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read

5.4
CVE-2026-54256

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

6.8
CVE-2026-47837

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spri

6.8
CVE-2026-32639

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

5.9
CVE-2026-32593

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

6.5
CVE-2026-81034

Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started