Security Risk Severity

Medium Security Risks — Page 8

Published vulnerability pages grouped by medium severity. Use this page to review risks that need similar prioritization.

969 published medium risks

Medium severity

Showing 253–288 of 969 published risks.

Clear
medium

CVE-2026-16332 DNS-320 vulnerability

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVE-2026-16332phpauthorization-bypassfile-upload

Updated Jul 21, 2026

medium

CVE-2026-16330 DNS-320 vulnerability

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVE-2026-16330phpauthorization-bypassfile-upload

Updated Jul 21, 2026

medium

CVE-2026-16331 DNS-320 vulnerability

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-16331phpauthorization-bypassfile-upload

Updated Jul 21, 2026

medium

CVE-2026-63729 TeX Live vulnerability

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.

CVE-2026-63729remote-code-executionmemory-corruption

Updated Jul 21, 2026

medium

CVE-2026-16336 trino vulnerability

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-16336javaopen-redirect

Updated Jul 21, 2026

medium

CVE-2026-15811 Red Hat Enterprise Linux 10 vulnerability

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.

CVE-2026-15811linux

Updated Jul 21, 2026

medium

CVE-2026-15812 Red Hat Enterprise Linux 10 vulnerability

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.

CVE-2026-15812linuxauthentication-bypassauthorization-bypass

Updated Jul 21, 2026

medium

CVE-2023-37507 DevOps Plan vulnerability

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

CVE-2023-37507devopsinformation-disclosure

Updated Jul 21, 2026

medium

CVE-2026-15927 mirror registry for Red Hat OpenShift 2 vulnerability

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.

CVE-2026-15927api-securityssrf

Updated Jul 21, 2026

medium

CVE-2026-3182 ManageEngine Endpoint Central vulnerability

Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

CVE-2026-3182information-disclosure

Updated Jul 21, 2026

medium

CVE-2026-8593 Checkmk vulnerability

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules

CVE-2026-8593authorization-bypass

Updated Jul 21, 2026

medium

CVE-2026-15370 Red Hat Enterprise Linux 10 vulnerability

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

CVE-2026-15370linuxnetwork-security

Updated Jul 21, 2026

medium

CVE-2026-64606 Apache Fory vulnerability

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

CVE-2026-64606javaunsafe-deserialization

Updated Jul 21, 2026

medium

CVE-2026-64608 Apache Fory vulnerability

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not. This issue affects Apache Fory C++: from 0.14.0 before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

CVE-2026-64608information-disclosurememory-corruptionunsafe-deserialization

Updated Jul 21, 2026

medium

CVE-2026-62415 Membership Pro extension for Joomla vulnerability

The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

CVE-2026-62415joomla

Updated Jul 21, 2026

medium

CVE-2026-64609 Apache Fory vulnerability

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected. This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

CVE-2026-64609information-disclosure

Updated Jul 21, 2026

mediumEPSS 0.007

CVE-2026-56649 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

CVE-2026-56649windowsmemory-corruptionrace-condition

Updated Jul 19, 2026

mediumEPSS 0.005

CVE-2026-57083 windows 10 1607 vulnerability

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

CVE-2026-57083windowsmicrosoft

Updated Jul 19, 2026

mediumEPSS 0.005

CVE-2026-57084 windows 10 1607 vulnerability

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

CVE-2026-57084windows

Updated Jul 19, 2026

mediumEPSS 0.003

CVE-2026-57085 windows 10 1607 vulnerability

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

CVE-2026-57085windowsinformation-disclosure

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48253 experience manager vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVE-2026-48253browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48254 experience manager vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVE-2026-48254browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48255 experience manager vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVE-2026-48255browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48257 experience manager vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVE-2026-48257browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48260 experience manager vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVE-2026-48260browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48261 experience manager vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVE-2026-48261browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48262 experience manager vulnerability

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVE-2026-48262browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48263 experience manager vulnerability

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

CVE-2026-48263browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-48355 experience manager vulnerability

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

CVE-2026-48355browserxss

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-56742 cilium vulnerability

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.

CVE-2026-56742network-securityapi-securityauthorization-bypass

Updated Jul 19, 2026

mediumEPSS 0.002

CVE-2026-56743 cilium vulnerability

Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.

CVE-2026-56743cloud-securityauthorization-bypass

Updated Jul 19, 2026

mediumEPSS 0.003

CVE-2026-55608 n8n-mcp vulnerability

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true could allow an authenticated tenant to access default-scope workflow_versions backups instead of being confined to the tenant scope, exposing or deleting workflow-version backups from prior single-tenant deployments or migrations. This issue is fixed in version 2.57.4.

CVE-2026-55608authorization-bypassinformation-disclosure

Updated Jul 19, 2026

mediumEPSS 0.008

Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.

CVE-2026-15457wordpresspath-traversalfile-deletion

Updated Jul 19, 2026

mediumEPSS 0.003

pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read

The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract force generation of a full-site backup archive written to a publicly accessible directory, exposing wp-config.php database credentials, WordPress secret salts, and the complete PHP source tree. The resulting archive is deposited in the plugin's unprotected tmp/ directory at a predictable URL, making the extracted data accessible to unauthenticated visitors once the backup is triggered.

CVE-2026-14503wordpressphpauthorization-bypassinformation-disclosure

Updated Jul 19, 2026

mediumEPSS 0.003

ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary company locations in the ERP database.

CVE-2026-15349wordpresswoocommerceauthorization-bypass

Updated Jul 19, 2026

mediumEPSS 0.002

Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was partially patched in 5.0.7.

CVE-2026-2594wordpressxss

Updated Jul 19, 2026