Security Risk Severity
Medium Security Risks — Page 15
Published vulnerability pages grouped by medium severity. Use this page to review risks that need similar prioritization.
969 published medium risks
Medium severity
Showing 505–540 of 969 published risks.
CVE-2026-55135 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-56157 in Microsoft SharePoint Server
Microsoft SharePoint Server has an access control issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-45070 in Symfony MIME
Symfony MIME can allow email header injection through unsafe MIME parameter names.
Updated Jul 15, 2026
CVE-2026-45073 in Symfony Cache
Symfony Cache can build unsafe SQL when an untrusted cache prefix reaches PdoAdapter clear.
Updated Jul 15, 2026
CVE-2026-47212 in Symfony Twilio Notifier
Symfony Twilio Notifier ignored the Twilio signature header, so fake webhook events could be accepted.
Updated Jul 15, 2026
CVE-2026-47997 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47998 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47999 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can let a high-privilege user place script in vulnerable fields.
Updated Jul 15, 2026
CVE-2026-48000 in Adobe Commerce
Adobe Commerce has an open redirect issue that can send a user to an attacker-controlled site.
Updated Jul 15, 2026
CVE-2026-48371 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can let a low-privilege user place script in vulnerable fields.
Updated Jul 15, 2026
CVE-2026-48747 in Symfony Mailomat Mailer
Symfony Mailomat Mailer lets the request choose the HMAC algorithm for webhook signature checks.
Updated Jul 15, 2026
CVE-2026-48760 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can leave encoded visual-spoofing characters in URLs after sanitizing them.
Updated Jul 15, 2026
CVE-2026-48761 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can miss URL attributes in allowed HTML and let unsafe URLs pass through.
Updated Jul 15, 2026
CVE-2026-48784 in Symfony Routing
Symfony Routing can generate a URL that collapses to a different path when dot segments are normalized.
Updated Jul 15, 2026
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 - Authenticated (Customer+) Stored Cross-Site Scripting
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting
Breakdance has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting
Anti-Malware Security and Brute-Force Firewall has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.4 - Missing Authorization
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.
Updated Jul 15, 2026
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.11 - Missing Authorization
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.
Updated Jul 15, 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
SAML Single Sign On – SSO Login has a login security issue. In some setups, an attacker may be able to bypass SAML login checks.
Updated Jul 15, 2026
CVE-2026-47969 in Adobe Audition
Adobe Audition has an out-of-bounds read issue that can expose memory if a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-55054 in Microsoft Excel and Microsoft 365 Apps
Microsoft Excel has an out-of-bounds read issue that can disclose information when a user opens a crafted file.
Updated Jul 15, 2026
CVE-2026-45755 in Symfony Mailtrap Mailer
Symfony Mailtrap Mailer does not verify the Mailtrap webhook signature, so a remote attacker can send fake webhook events.
Updated Jul 15, 2026
CVE-2026-9341 in Academy LMS
Academy LMS lets a logged-in subscriber change a user id value and read, change, or delete another user's private lesson notes.
Updated Jul 15, 2026
CVE-2026-61952 in Bulk Edit Products for WooCommerce - WP Sheet Editor
Bulk Edit Products for WooCommerce - WP Sheet Editor misses an authorization check, so an author-level user can run an action they should not be allowed to run.
Updated Jul 15, 2026
CVE-2026-5135 in Red Hat Satellite
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.
Updated Jul 15, 2026
CVE-2026-5138 in Red Hat Satellite
A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.
Updated Jul 15, 2026
CVE-2026-5142 in Red Hat Satellite
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Updated Jul 15, 2026
CVE-2026-6683 in FatFs
FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to be zero during write/sync operations. This maps to CWE-369 (Divide By Zero). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). Network-delivered update media can make this remote in some pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.
Updated Jul 15, 2026
CVE-2026-6684 in FatFs
FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.
Updated Jul 15, 2026
CVE-2026-6685 in FatFs
FatFs R0.16 and earlier exhibits a stale dirty-cache skip via unsigned-subtraction wrap in f_read() / f_write() (fp->sect - sect < cc) during interleaved read/write on fragmented filesystems. This maps to CWE-191 (Integer Underflow). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H (6.1, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.
Updated Jul 15, 2026
CVE-2026-6686 in FatFs
FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.
Updated Jul 15, 2026
CVE-2026-24266 in NVIDIA Triton Inference Server
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.
Updated Jul 15, 2026
CVE-2026-58024 in MediaWiki
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiUserrights.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Updated Jul 15, 2026
CVE-2026-58025 in MediaWiki
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Updated Jul 15, 2026
CVE-2026-58027 in MediaWiki AbuseFilter
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php. This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Updated Jul 15, 2026
