Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 84/1777
5.5
CVE-2026-64213

In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Add lock protection to lm90_alert Sa

5.5
CVE-2026-64212

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer bef

5.5
CVE-2026-64211

In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-onlin

6.1
CVE-2026-8308

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa

4.6
CVE-2026-7007

The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.

6.5
CVE-2026-66007

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder

5.3
CVE-2026-66006

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs

6.3
CVE-2026-66005

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that

5.3
CVE-2026-66004

BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all

6.5
CVE-2026-49326

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest

6.5
CVE-2026-17059

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa

6.5
CVE-2026-16802

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear

5.0
CVE-2026-16799

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and

6.5
CVE-2026-16798

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.

5.5
CVE-2026-17048

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w

5.3
CVE-2026-7484

External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Fu

6.1
CVE-2026-66010

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL

5.3
CVE-2026-46452

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken dat

6.5
CVE-2026-45812

Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event.

5.5
CVE-2026-16743

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root

5.5
CVE-2026-16730

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer set

4.9
CVE-2026-15663

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injecti

5.6
CVE-2026-63317

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:

6.1
CVE-2026-56392

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation

6.1
CVE-2026-56391

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch

6.4
CVE-2026-15821

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v

6.4
CVE-2026-15739

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination'

6.1
CVE-2026-15346

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '

4.9
CVE-2026-12702

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to

5.5
CVE-2026-16910

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc

6.4
CVE-2026-15755

The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short

6.4
CVE-2026-15665

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S

6.4
CVE-2026-15653

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S

6.4
CVE-2026-15648

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri

6.4
CVE-2026-15464

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att

6.4
CVE-2026-15334

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress

6.4
CVE-2026-15333

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress

5.3
CVE-2026-12654

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up

5.4
CVE-2026-12689

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr

6.5
CVE-2026-12688

The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group mem

4.8
CVE-2026-66139

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

5.5
CVE-2026-54422

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m

6.4
CVE-2026-6454

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu

4.3
CVE-2026-15420

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory

6.4
CVE-2026-15100

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnore

5.3
CVE-2026-13464

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob

6.5
CVE-2026-11922

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST

5.3
CVE-2026-11354

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an

6.4
CVE-2025-9205

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.

6.5
CVE-2026-49159

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started