Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 9/1777
4.4
CVE-2026-76149

CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.

5.3
CVE-2026-73335

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A m

4.2
CVE-2026-70665

Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeep

5.4
CVE-2026-55805

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core

5.7
CVE-2026-18261

Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.

5.7
CVE-2026-18260

Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.

5.7
CVE-2026-16646

Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.

5.7
CVE-2026-16643

Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.

5.7
CVE-2026-16642

Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.

6.1
CVE-2026-16640

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API

6.1
CVE-2026-16638

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folde

4.7
CVE-2026-15917

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core

4.2
CVE-2026-15916

Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versi

5.7
CVE-2026-15088

Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.

5.7
CVE-2026-80185

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested Ser

6.8
CVE-2026-73180

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP se

4.4
CVE-2026-80101

A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validate

4.3
CVE-2026-79793

A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown

5.6
CVE-2026-79792

A flaw has been found in zackees transcribe-anything up to 4.1.0. Affected is the function ytdlp_download of the file sr

6.5
CVE-2026-79293

Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive info

6.5
CVE-2026-79291

Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informatio

6.5
CVE-2026-79288

Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to

5.3
CVE-2026-79287

Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive in

6.5
CVE-2026-79285

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtai

4.3
CVE-2026-79284

UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had comprom

5.4
CVE-2026-79283

UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements

4.3
CVE-2026-79276

Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging

4.3
CVE-2026-79274

Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data vi

4.3
CVE-2026-79273

Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacke

6.5
CVE-2026-79271

Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

6.5
CVE-2026-79270

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside

4.3
CVE-2026-79269

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass

4.3
CVE-2026-79267

Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rend

5.3
CVE-2026-79265

Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

4.3
CVE-2026-79264

Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass we

4.3
CVE-2026-79262

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi

4.3
CVE-2026-79261

Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web orig

6.5
CVE-2026-79260

Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

4.3
CVE-2026-79259

Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass sy

6.5
CVE-2026-79258

Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social eng

4.3
CVE-2026-79254

Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote atta

6.5
CVE-2026-79253

Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker lev

4.3
CVE-2026-79252

Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-orig

4.3
CVE-2026-79251

Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially by

5.4
CVE-2026-79250

UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address ba

6.5
CVE-2026-79249

Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inform

4.3
CVE-2026-79248

Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

6.5
CVE-2026-79246

Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i

6.5
CVE-2026-79243

Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker

5.3
CVE-2026-79242

Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started