Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 98/1777
5.8
CVE-2026-15811

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not

4.9
CVE-2026-15782

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres

6.4
CVE-2026-15156

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored

6.1
CVE-2023-37508

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v

6.8
CVE-2026-59776

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v

4.3
CVE-2026-16336

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/jav

6.6
CVE-2026-63729

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince co

6.3
CVE-2026-16334

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code o

6.3
CVE-2026-63728

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence r

6.4
CVE-2026-64626

AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the en

5.6
CVE-2026-57852

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att

6.9
CVE-2026-51385

An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code v

6.1
CVE-2026-51025

Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary

5.5
CVE-2026-47144

Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame

6.1
CVE-2026-47128

nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landloc

6.4
CVE-2026-12900

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S

5.4
CVE-2026-58624

Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server

5.3
CVE-2026-55219

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the

5.3
CVE-2026-53596

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeSco

4.9
CVE-2026-53594

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Lo

5.4
CVE-2026-44585

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the

4.3
CVE-2026-44584

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the

5.3
CVE-2026-44583

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the

4.6
CVE-2026-53592

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th

6.1
CVE-2026-44230

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10

5.4
CVE-2026-44229

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to bo

4.3
CVE-2026-63768

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows at

5.0
CVE-2026-63730

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir

6.1
CVE-2026-61901

Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an

5.3
CVE-2026-55639

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Se

6.5
CVE-2026-45295

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tr

5.4
CVE-2026-44228

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, conta

6.1
CVE-2026-44227

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contai

6.1
CVE-2026-26483

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template managemen

5.5
CVE-2026-64207

In the Linux kernel, the following vulnerability has been resolved: net/sched: dualpi2: fix GSO backlog accounting Whe

5.5
CVE-2026-64205

In the Linux kernel, the following vulnerability has been resolved: i2c: i801: fix hardware state machine corruption in

5.5
CVE-2026-64192

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if

5.5
CVE-2026-64190

In the Linux kernel, the following vulnerability has been resolved: net: team: fix NULL pointer dereference in team_xmi

5.5
CVE-2026-64187

In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no

5.9
CVE-2026-58482

Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalI

6.5
CVE-2026-58481

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped fil

5.5
CVE-2026-58414

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recu

6.1
CVE-2026-58413

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, b

6.5
CVE-2026-55645

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client

5.3
CVE-2026-55238

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Co

5.4
CVE-2026-50743

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or

6.5
CVE-2026-47276

In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attac

5.3
CVE-2026-44978

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the

5.3
CVE-2026-42218

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in

5.5
CVE-2026-35590

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and in

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started