Security Risk Severity

Medium Security Risks — Page 11

Published vulnerability pages grouped by medium severity. Use this page to review risks that need similar prioritization.

969 published medium risks

Medium severity

Showing 361–396 of 969 published risks.

Clear
mediumEPSS 0.002

CVE-2026-47979 media encoder vulnerability

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47979information-disclosure

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-48308 premiere pro vulnerability

Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48308input-validation

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-48296 c2pa vulnerability

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-48296input-validation

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-48298 c2pa vulnerability

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-48298input-validation

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-48302 c2pa vulnerability

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-48302input-validation

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-48312 c2pa vulnerability

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.

CVE-2026-48312input-validation

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-48353 c2pa vulnerability

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48353input-validationfile-write

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-48354 c2pa vulnerability

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-48354input-validation

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-48357 c2pa vulnerability

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-48357denial-of-service

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-48805 twig vulnerability

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0.

CVE-2026-48805php

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-48808 twig vulnerability

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.

CVE-2026-48808phpauthorization-bypass

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-49981 twig vulnerability

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.

CVE-2026-49981phpauthorization-bypass

Updated Jul 17, 2026

mediumEPSS 0.001

CVE-2026-59732 rclone vulnerability

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.

CVE-2026-59732path-traversal

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-56353 n8n vulnerability

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.

CVE-2026-56353authentication-bypass

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-59259 n8n vulnerability

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential create or update permissions but without the externalSecret:list scope can embed external secret references into credentials in forms the static validation does not detect; these references resolve at workflow execution time, exposing secret values the user is not authorized to access. This issue only affects instances where an external secrets provider is configured and Advanced Permissions are in use.

CVE-2026-59259authorization-bypassidor

Updated Jul 17, 2026

mediumEPSS 0.001

CVE-2026-61859 imagemagick vulnerability

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

CVE-2026-61859path-traversal

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-20146 identity services engine passive identity connector vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.

CVE-2026-20146path-traversalfile-writefile-deletion

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-33444 secure access vulnerability

CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.

CVE-2026-33444denial-of-servicememory-corruption

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-55398 secure access vulnerability

CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.

CVE-2026-55398denial-of-servicememory-corruption

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-55399 secure access vulnerability

CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.

CVE-2026-55399denial-of-service

Updated Jul 17, 2026

medium

CVE-2025-43892 in Fortinet FortiProxy

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.

CVE-2025-43892network-securityinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-50678 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50678microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.005

CVE-2026-48580 in Microsoft 365 Apps

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-48580microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-50408 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50408microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-55121 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55121microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-55138 in Microsoft 365 Apps

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55138microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-55898 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55898microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.005

CVE-2026-45754 in Symfony Mailer and Notifier Bridges

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

CVE-2026-45754phpinput-validationauthentication-bypass

Updated Jul 16, 2026

mediumEPSS 0.005

CVE-2026-48736 in Symfony HttpClient

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

CVE-2026-48736phpinput-validationssrf

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15766 in Google Chrome

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15766browserinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15768 in Google Chrome

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15768browserauthorization-bypass

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15770 in Google Chrome

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15770browserinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15771 in Google Chrome

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15771browserwindowsinput-validationinformation-disclosure

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15775 in Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15775browserauthorization-bypass

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15778 in Google Chrome

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-15778browserinput-validationauthorization-bypass

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-48338 in Adobe ColdFusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48338web-applicationinformation-disclosurepath-traversalfile-write

Updated Jul 16, 2026