Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 79/1777
5.4
CVE-2026-66746

Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arb

5.4
CVE-2026-62828

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a netw

5.5
CVE-2026-7521

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deleti

5.3
CVE-2026-66299

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache To

6.5
CVE-2026-61487

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated

6.1
CVE-2026-65882

Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle w

6.5
CVE-2026-62436

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

6.5
CVE-2026-62435

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

5.3
CVE-2026-62434

A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. Thi

6.5
CVE-2026-62429

Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cl

5.5
CVE-2026-62425

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

5.5
CVE-2026-62424

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

5.5
CVE-2026-62423

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

5.5
CVE-2026-42495

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

6.1
CVE-2026-42494

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

6.5
CVE-2026-18047

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching fo

4.3
CVE-2026-18038

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.E

6.4
CVE-2026-15393

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress

6.4
CVE-2026-15016

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab

5.3
CVE-2026-16774

The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the

5.3
CVE-2026-16773

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive In

4.9
CVE-2026-15444

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the

5.3
CVE-2026-15411

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for

5.3
CVE-2026-13110

The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin

4.3
CVE-2026-58246

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn

5.0
CVE-2026-11598

The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all

5.8
CVE-2026-9680

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP

6.1
CVE-2026-8167

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu

5.2
CVE-2026-44387

ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I

6.5
CVE-2026-15267

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL

6.1
CVE-2026-14171

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick

6.4
CVE-2026-15730

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is

4.4
CVE-2026-15673

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

4.9
CVE-2026-15671

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

4.9
CVE-2026-15670

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

5.9
CVE-2024-14041

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno

6.5
CVE-2026-6251

The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i

4.9
CVE-2026-16811

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-bas

4.3
CVE-2026-16797

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure

4.3
CVE-2026-16587

The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in

4.3
CVE-2026-15136

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery

5.3
CVE-2026-15012

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory C

4.2
CVE-2026-14926

The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the

5.3
CVE-2026-12124

The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for Word

6.1
CVE-2026-17528

Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element.

6.5
CVE-2026-65448

Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.

6.5
CVE-2026-65445

Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

6.1
CVE-2026-51565

Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker

6.1
CVE-2026-53669

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backsl

6.9
CVE-2026-53668

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started