Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 77/1777
6.5
CVE-2026-13346

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo

6.5
CVE-2026-59920

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina

5.5
CVE-2026-59919

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina

5.3
CVE-2026-59900

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,

6.3
CVE-2026-54705

MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode conten

6.5
CVE-2026-13723

A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrar

6.5
CVE-2026-67194

Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process

5.3
CVE-2026-20316 KEV

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti

5.6
CVE-2026-18257

Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a cert

4.8
CVE-2026-16729

undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before

5.3
CVE-2026-67193

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to

6.5
CVE-2026-54082

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve

5.9
CVE-2026-50558

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d

5.5
CVE-2026-17550

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili

6.1
CVE-2026-16465

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili

6.1
CVE-2026-54663

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol

5.3
CVE-2026-67217

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a repl

5.9
CVE-2026-67216

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the

5.9
CVE-2026-67214

nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its no

5.9
CVE-2026-67213

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these fun

6.1
CVE-2026-66490

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

5.3
CVE-2026-66489

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

5.3
CVE-2026-66488

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

4.8
CVE-2026-66400

Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh

5.3
CVE-2026-18174

@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header

6.5
CVE-2026-16751

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an auth

6.1
CVE-2026-65946

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

6.5
CVE-2026-65891

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function

6.4
CVE-2026-8791

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl`

6.4
CVE-2026-7436

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text

4.9
CVE-2026-6089

The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor

6.5
CVE-2026-5060

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure D

6.3
CVE-2026-56390

GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyi

5.3
CVE-2026-4604

The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing

4.8
CVE-2026-65100

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so

5.9
CVE-2026-58185

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 t

5.9
CVE-2026-58183

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apach

6.5
CVE-2026-58160

Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0

5.9
CVE-2026-58158

Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects A

6.5
CVE-2026-18207

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group m

5.5
CVE-2026-18201

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discov

4.3
CVE-2026-9720

The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions

4.8
CVE-2026-65325

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the n

4.9
CVE-2026-58156

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affe

5.9
CVE-2026-58152

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apa

4.9
CVE-2026-11973

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a

6.5
CVE-2026-35226

An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same n

5.9
CVE-2026-33930

Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handl

6.1
CVE-2026-18197

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allow

6.5
CVE-2026-18192

VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to e

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started