Security Risk Severity

Medium Security Risks — Page 15

Published vulnerability pages grouped by medium severity. Use this page to review risks that need similar prioritization.

969 published medium risks

Medium severity

Showing 505–540 of 969 published risks.

Clear
mediumEPSS 0.003

CVE-2026-55135 in Microsoft SharePoint Server

Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.

CVE-2026-55135windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56157 in Microsoft SharePoint Server

Microsoft SharePoint Server has an access control issue that can let an authorized attacker spoof content over the network.

CVE-2026-56157windowsmicrosoftweb-applicationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-45070 in Symfony MIME

Symfony MIME can allow email header injection through unsafe MIME parameter names.

CVE-2026-45070phpweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.005

CVE-2026-45073 in Symfony Cache

Symfony Cache can build unsafe SQL when an untrusted cache prefix reaches PdoAdapter clear.

CVE-2026-45073phpweb-applicationsql-injection

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-47212 in Symfony Twilio Notifier

Symfony Twilio Notifier ignored the Twilio signature header, so fake webhook events could be accepted.

CVE-2026-47212phpweb-applicationauthentication-bypasscryptography

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-47997 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.

CVE-2026-47997phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-47998 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.

CVE-2026-47998phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.115

CVE-2026-47999 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can let a high-privilege user place script in vulnerable fields.

CVE-2026-47999phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-48000 in Adobe Commerce

Adobe Commerce has an open redirect issue that can send a user to an attacker-controlled site.

CVE-2026-48000phpweb-applicationopen-redirect

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-48371 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can let a low-privilege user place script in vulnerable fields.

CVE-2026-48371phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-48747 in Symfony Mailomat Mailer

Symfony Mailomat Mailer lets the request choose the HMAC algorithm for webhook signature checks.

CVE-2026-48747phpweb-applicationauthentication-bypasscryptography

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48760 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can leave encoded visual-spoofing characters in URLs after sanitizing them.

CVE-2026-48760phpweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48761 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can miss URL attributes in allowed HTML and let unsafe URLs pass through.

CVE-2026-48761phpweb-applicationinput-validationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48784 in Symfony Routing

Symfony Routing can generate a URL that collapses to a different path when dot segments are normalized.

CVE-2026-48784phpweb-applicationinput-validationopen-redirect

Updated Jul 15, 2026

mediumEPSS 0.002

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 - Authenticated (Customer+) Stored Cross-Site Scripting

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57711wordpressbrowserxss

Updated Jul 15, 2026

medium

Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting

Breakdance has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57735wordpressbrowserxss

Updated Jul 15, 2026

mediumEPSS 0.002

Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting

Anti-Malware Security and Brute-Force Firewall has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57691wordpressbrowsernetwork-securityxss

Updated Jul 15, 2026

mediumEPSS 0.002

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.4 - Missing Authorization

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.

CVE-2026-57812wordpressauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.11 - Missing Authorization

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.

CVE-2026-59523wordpressauthorization-bypass

Updated Jul 15, 2026

medium

SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion

SAML Single Sign On – SSO Login has a login security issue. In some setups, an attacker may be able to bypass SAML login checks.

CVE-2026-15013wordpressauthentication-bypasssaml

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-47969 in Adobe Audition

Adobe Audition has an out-of-bounds read issue that can expose memory if a user opens a malicious file.

CVE-2026-47969windowsinformation-disclosurememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-55054 in Microsoft Excel and Microsoft 365 Apps

Microsoft Excel has an out-of-bounds read issue that can disclose information when a user opens a crafted file.

CVE-2026-55054windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-45755 in Symfony Mailtrap Mailer

Symfony Mailtrap Mailer does not verify the Mailtrap webhook signature, so a remote attacker can send fake webhook events.

CVE-2026-45755phpweb-applicationinput-validationauthentication-bypass

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-9341 in Academy LMS

Academy LMS lets a logged-in subscriber change a user id value and read, change, or delete another user's private lesson notes.

CVE-2026-9341wordpressauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-61952 in Bulk Edit Products for WooCommerce - WP Sheet Editor

Bulk Edit Products for WooCommerce - WP Sheet Editor misses an authorization check, so an author-level user can run an action they should not be allowed to run.

CVE-2026-61952wordpresswoocommerceauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5135 in Red Hat Satellite

A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.

CVE-2026-5135linuxdevopsweb-applicationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5138 in Red Hat Satellite

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.

CVE-2026-5138linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-5142 in Red Hat Satellite

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

CVE-2026-5142linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6683 in FatFs

FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to be zero during write/sync operations. This maps to CWE-369 (Divide By Zero). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). Network-delivered update media can make this remote in some pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

CVE-2026-6683supply-chaindenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6684 in FatFs

FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

CVE-2026-6684supply-chaindenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6685 in FatFs

FatFs R0.16 and earlier exhibits a stale dirty-cache skip via unsigned-subtraction wrap in f_read() / f_write() (fp->sect - sect < cc) during interleaved read/write on fragmented filesystems. This maps to CWE-191 (Integer Underflow). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H (6.1, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.

CVE-2026-6685supply-chaininput-validation

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6686 in FatFs

FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

CVE-2026-6686supply-chaininformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-24266 in NVIDIA Triton Inference Server

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.

CVE-2026-24266linuxdevopsdenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58024 in MediaWiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiUserrights.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58024phpapi-securityweb-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.005

CVE-2026-58025 in MediaWiki

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58025phpweb-applicationremote-code-executionfile-write

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58027 in MediaWiki AbuseFilter

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php. This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58027phpapi-securityweb-applicationinformation-disclosure

Updated Jul 15, 2026