Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 90/1777
4.3
CVE-2026-63145

Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification

6.5
CVE-2026-63144

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s

4.3
CVE-2026-63143

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122

5.0
CVE-2026-63142

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reportin

4.3
CVE-2026-16486

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the f

4.3
CVE-2026-16485

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

5.4
CVE-2026-16415

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attac

6.8
CVE-2026-8989

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through e

6.8
CVE-2026-8988

Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of th

6.5
CVE-2026-65316

XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read

4.3
CVE-2026-65314

Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to i

6.3
CVE-2026-63141

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration

5.4
CVE-2026-62563

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor

6.5
CVE-2026-62562

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.8
CVE-2026-62559

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.5
CVE-2026-62556

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.3
CVE-2026-62542

Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Su

6.3
CVE-2026-62528

Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Suppor

6.3
CVE-2026-62527

Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supp

6.3
CVE-2026-62525

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supp

6.3
CVE-2026-62524

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported v

6.3
CVE-2026-62519

Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Suppor

5.3
CVE-2026-62517

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).

5.3
CVE-2026-62507

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

6.1
CVE-2026-62505

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

6.7
CVE-2026-62503

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

5.3
CVE-2026-62490

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

4.2
CVE-2026-62489

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

6.5
CVE-2026-62488

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

6.1
CVE-2026-62487

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

5.0
CVE-2026-62486

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

5.9
CVE-2026-62484

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

4.3
CVE-2026-62483

Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp

5.4
CVE-2026-62482

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

6.5
CVE-2026-62480

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

5.4
CVE-2026-62479

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

6.3
CVE-2026-62474

Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring)

6.5
CVE-2026-62470

Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Ser

6.6
CVE-2026-62465

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.3
CVE-2026-62453

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.1
CVE-2026-62444

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

6.6
CVE-2026-61328

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve

6.5
CVE-2026-61323

Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The

4.3
CVE-2026-61316

Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar

4.3
CVE-2026-61315

Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar

6.3
CVE-2026-61304

Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Suppo

6.3
CVE-2026-61294

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchro

4.3
CVE-2026-61292

Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).

6.3
CVE-2026-61283

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Web Services). Supported v

6.3
CVE-2026-61282

Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Su

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started