Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 82/1777
5.4
CVE-2026-66442

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

5.3
CVE-2026-66438

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

4.9
CVE-2026-66437

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

6.5
CVE-2026-66434

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

6.5
CVE-2026-66433

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

4.3
CVE-2026-66428

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

5.0
CVE-2026-65568

Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

5.3
CVE-2026-65567

Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

5.3
CVE-2026-65564

Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

5.9
CVE-2026-65563

Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

6.5
CVE-2026-65562

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

6.5
CVE-2026-65561

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

5.4
CVE-2026-65558

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

5.9
CVE-2026-65557

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

6.8
CVE-2026-65436

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

6.5
CVE-2026-65435

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

6.5
CVE-2026-65434

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

6.5
CVE-2026-65433

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

6.5
CVE-2026-59560

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

6.5
CVE-2026-59559

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 version

6.5
CVE-2026-59557

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

6.5
CVE-2026-10819

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number o

4.3
CVE-2026-10600

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and

5.3
CVE-2026-17514

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Ex

5.6
CVE-2026-15003

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125

5.9
CVE-2026-66053

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affect

6.5
CVE-2026-55970

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a

5.5
CVE-2026-17534

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal

6.5
CVE-2026-66412

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston

6.8
CVE-2026-14827

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in

5.3
CVE-2026-14820

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log

6.5
CVE-2026-14568

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor

4.7
CVE-2026-14236

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it

4.8
CVE-2026-14203

The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML

6.1
CVE-2026-14190

The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input

6.1
CVE-2026-13400

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and incl

5.3
CVE-2026-13390

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega

6.1
CVE-2026-12982

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it

6.1
CVE-2026-10082

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it

5.3
CVE-2026-17501

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file commo

5.3
CVE-2026-17500

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file

5.4
CVE-2026-57978

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

4.3
CVE-2026-17459

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.exter

6.3
CVE-2026-17458

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file s

4.3
CVE-2026-17457

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserN

6.3
CVE-2026-17434

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/mod

5.3
CVE-2026-17433

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of t

5.0
CVE-2026-17432

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functio

6.5
CVE-2026-10681

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thre

5.5
CVE-2026-64297

In the Linux kernel, the following vulnerability has been resolved: module: decompress: check return value of module_ex

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started