By severity

Medium-severity vulnerabilities

CVEs rated Medium by CVSS, with SEC.co remediation and prioritization guidance.

4010 published vulnerabilities · page 5 of 41

  • CVE-2026-14019MEDIUM 6.5

    A flaw in Google Chrome's password manager implementation allowed attackers to steal sensitive cross-origin data through a specially crafted webpage. The vulnerability required user interaction—specifically clicking on a malicious HTML page—but did not require any special privileges or complex setup to exploit. Chrome versions prior to 150.0.7871.47 are affected.

  • CVE-2026-14021MEDIUM 6.5

    A vulnerability in Google Chrome's StorageAccessAPI allows a remote attacker who has already compromised a user's Chrome renderer process to steal data from other websites that the user has visited. This requires both renderer compromise and user interaction with a malicious webpage, but if achieved, could leak sensitive cross-origin information. Chrome version 150.0.7871.47 and later address this issue.

  • CVE-2026-14022MEDIUM 6.5

    Google Chrome versions before 150.0.7871.47 contain a flaw that allows attackers who have already compromised Chrome's renderer process to steal data from websites the user visits. The vulnerability stems from inadequate validation of network input and requires an attacker to first gain control of the renderer—typically through a separate browser exploit—then use a specially crafted webpage to exfiltrate sensitive cross-origin information that should be protected from access.

  • CVE-2026-14023MEDIUM 6.5

    A flaw in Google Chrome's input validation allows attackers to bypass the same-origin policy—a fundamental browser security boundary—by sending users a specially crafted web page. This could enable unauthorized access to sensitive data from other websites the user is logged into. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction (visiting a malicious page).

  • CVE-2026-14029MEDIUM 6.5

    Groundhogg, a WordPress plugin used for customer relationship management, newsletters, and marketing automation, contains a SQL injection flaw that allows authenticated users with certain privileges to extract sensitive data from the database. The vulnerability exists in versions up to 4.5.8 and is triggered through the 'select' parameter, which the plugin fails to properly sanitize before using in database queries. While exploitation requires an attacker to already have a Groundhogg user account with custom-level access or higher, the capability needed (view_contacts) is granted by default to most built-in Groundhogg roles above subscriber level, making it a realistic threat for organizations running this plugin.

  • CVE-2026-14033MEDIUM 6.5

    Google Chrome on Windows contains a weakness in how it enforces policies related to media handling. An attacker can craft a malicious webpage that, when visited by a user, bypasses Chrome's site isolation feature—a critical security boundary that prevents one website from accessing data or capabilities of another. The vulnerability requires user interaction (clicking a link, visiting a page) and affects Chrome versions before 150.0.7871.47. While Chromium rates this as low severity internally, the CVSS score of 6.5 reflects the integrity impact of circumventing site isolation, making it a medium-severity concern in standard vulnerability assessment frameworks.

  • CVE-2026-14035MEDIUM 6.5

    Google Chrome versions prior to 150.0.7871.47 contain a Bluetooth-related security flaw that allows an attacker to extract sensitive information from the browser's memory. An attacker would need to trick a user into visiting a malicious webpage; if successful, the attacker could read data that shouldn't be accessible, such as authentication tokens, session data, or other confidential information stored in memory. Chrome itself rates this as low severity, though the CVSS score reflects moderate risk due to the ease of exploitation and the sensitivity of potential data exposure.

  • CVE-2026-14048MEDIUM 6.5

    A use-after-free flaw in Google Chrome's Chromecast component allows an attacker positioned on the same local network to extract sensitive data from the browser's memory using a specially crafted malicious peripheral device. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.

  • CVE-2026-14050MEDIUM 6.5

    A weakness in how Google Chrome enforces security policies for the Passwords feature before version 150.0.7871.47 could allow an attacker to trick users into visiting a malicious webpage that leaks sensitive data across different websites. The attacker cannot directly compromise the browser; instead, they must craft a convincing HTML page and convince the user to visit it. Once a user is on that page, the vulnerability permits unauthorized access to information from other origins—effectively bypassing the browser's same-origin policy protections.

  • CVE-2026-14051MEDIUM 6.5

    A memory disclosure vulnerability exists in Google Chrome's GamepadAPI prior to version 150.0.7871.47. An attacker who has already compromised Chrome's renderer process can craft a malicious webpage to read uninitialized memory, potentially exposing sensitive data. The vulnerability requires user interaction (visiting a crafted page) and prior renderer compromise, making it a secondary risk in multi-stage attack chains rather than an entry vector.

  • CVE-2026-14059MEDIUM 6.5

    A security weakness in Google Chrome's Related-Website-Sets feature allows attackers to trick users into visiting a malicious webpage that can steal data from other websites the user is logged into. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction (clicking a link or visiting the malicious page). While the Chromium project rated this as low severity, the CVSS score reflects a medium-risk profile because of its potential to expose sensitive cross-origin information without the user's knowledge.

  • CVE-2026-14061MEDIUM 6.5

    A flaw in Google Chrome's Dawn graphics component allows attackers to trick users into visiting specially crafted web pages that can leak sensitive information from the browser's memory. The vulnerability requires user interaction—the victim must visit a malicious site—but once they do, attackers may be able to read data that should remain private, such as authentication tokens or other browser state. This affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.

  • CVE-2026-14065MEDIUM 6.5

    CVE-2026-14065 is a navigation-bypass vulnerability in Google Chrome versions before 150.0.7871.47. An attacker who has already compromised Chrome's renderer process (the component that executes web page content) can craft a malicious HTML page to circumvent built-in navigation security controls. While this requires prior renderer compromise, the impact allows unauthorized navigation to restricted destinations. The Chromium project rates this as low severity, though the CVSS score of 6.5 reflects the potential for integrity violation.

  • CVE-2026-14069MEDIUM 6.5

    An integer overflow vulnerability exists in the WebNN (Web Neural Network) component of Google Chrome versions before 150.0.7871.47. An attacker could craft a malicious HTML page that, when visited, exploits this flaw to read sensitive data from the browser's memory. The vulnerability requires user interaction (visiting a malicious site) but does not require any special privileges or system access.

  • CVE-2026-14070MEDIUM 6.5

    A memory safety vulnerability in Google Chrome's WebNN (Web Neural Network) component allows attackers to leak sensitive data from the browser's memory. An attacker can craft a malicious webpage that, when visited by a user, exploits an integer overflow to read unintended data from the running process. While Chrome classified this as low severity internally, the confidentiality impact warrants attention from a defense perspective.

  • CVE-2026-14071MEDIUM 6.5

    Google Chrome versions before 150.0.7871.47 contain a side-channel vulnerability in the WebAudio component that allows attackers to extract sensitive cross-origin data through a specially crafted webpage. An attacker would need to trick a user into visiting a malicious site, but once there, they could potentially read data from other websites the user has open—a serious breach of browser security boundaries. The vulnerability is rated MEDIUM severity due to its reliance on user interaction and limited scope of impact.

  • CVE-2026-14074MEDIUM 6.5

    A side-channel vulnerability in Google Chrome's WebAuthentication implementation on iOS allows an attacker to leak sensitive cross-origin data through a crafted web page. The flaw exists in Chrome versions before 150.0.7871.47 and requires user interaction to trigger. An attacker would craft a malicious HTML page that, when visited by a victim, exploits timing or behavioral differences in the WebAuthentication API to infer or extract data from other websites the user has authenticated to.

  • CVE-2026-14081MEDIUM 6.5

    Google Chrome versions before 150.0.7871.47 contain a flaw in DevTools policy enforcement that could allow an attacker to extract sensitive data from browser process memory. The vulnerability requires social engineering—convincing a user to install a malicious extension—but once installed, the extension can bypass DevTools restrictions to access confidential information. This is not a flaw users can trigger by visiting a website; it hinges on the user's decision to add untrusted code to their browser.

  • CVE-2026-14082MEDIUM 6.5

    A race condition in Google Chrome's storage subsystem allows attackers to access sensitive data across different websites through a specially crafted HTML page. The vulnerability requires user interaction—such as visiting a malicious webpage—but doesn't need special privileges or browser configuration to exploit. While Chromium's own severity rating is 'Low,' the confidentiality impact warrants a medium-severity classification due to the potential exposure of cross-origin data that should otherwise be isolated by browser security boundaries.

  • CVE-2026-14085MEDIUM 6.5

    A side-channel vulnerability in Google Chrome's CSS rendering engine allows attackers to extract sensitive cross-origin data through a specially crafted webpage. An attacker can trick a user into visiting a malicious site that leaks information from other sites the user has open in the same browser—such as authentication tokens, form data, or private content. The vulnerability requires user interaction (visiting the malicious page) but does not need special browser settings or elevated privileges. Chrome versions prior to 150.0.7871.47 are affected.

  • CVE-2026-14088MEDIUM 6.5

    A memory leakage vulnerability in Chrome's Canvas rendering on Android devices allows attackers to trick users into visiting a malicious webpage that can read sensitive data from the browser's memory. The attacker needs the user to interact with the page, but no special privileges or complex attack setup is required. Chrome versions prior to 150.0.7871.47 on Android are affected.

  • CVE-2026-14096MEDIUM 6.5

    A flaw in Google Chrome's input handling on Android could allow an attacker to steal sensitive information across different websites, but only if they've already compromised Chrome's renderer process—the engine that executes web content. The attacker would need to trick the user into visiting a specially crafted webpage. This is a medium-severity issue affecting Chrome versions before 150.0.7871.47.

  • CVE-2026-14098MEDIUM 6.5

    A flaw in how Google Chrome handles CSS allows an attacker to craft a malicious webpage that can read data from websites on different domains—a cross-origin information leak. The vulnerability affects Chrome versions before 150.0.7871.47. While the attack requires user interaction (visiting the malicious page), the potential impact is significant: sensitive information from other websites could be exposed to the attacker. This is classified as a medium-severity issue, though Chromium's own assessment rated the underlying CSS implementation flaw as low severity.

  • CVE-2026-14100MEDIUM 6.5

    CVE-2026-14100 is a data leakage vulnerability in Google Chrome's NetworkCache component that allows attackers to extract sensitive information across website boundaries. An attacker crafts a malicious HTML page and tricks a user into visiting it; the flaw then permits unauthorized access to data that should remain isolated between different websites. While Google rates the underlying defect as low severity, the practical impact—cross-origin data exposure—warrants a medium CVSS score because it requires user interaction but reliably compromises confidentiality.

  • CVE-2026-14103MEDIUM 6.5

    A use-after-free memory flaw in Google Chrome's SSL/TLS implementation on ChromeOS allows an attacker to craft a malicious webpage that, when visited, can leak sensitive data from the browser's memory. The vulnerability requires user interaction (visiting a malicious site) but does not require authentication and can run over the network. Chrome versions before 150.0.7871.47 are affected. While Chromium's security team rated this as Low severity, the CVSS 3.1 score of 6.5 reflects the potential for meaningful confidentiality impact.

  • CVE-2026-14118MEDIUM 6.5

    A flaw in Chrome's developer tools allows attackers to trick users into leaking sensitive data from other websites through a specially crafted web page. The vulnerability requires users to perform specific interactions within DevTools, making it a social engineering attack rather than something that exploits silently. While Chromium rates this as low severity, the ability to cross origin boundaries and steal data elevates the practical risk for users who frequently interact with sensitive websites.

  • CVE-2026-14119MEDIUM 6.5

    Google Chrome on Windows contains a type confusion vulnerability in its Bluetooth handling that could allow an attacker already present on your local network to read sensitive data from Chrome's process memory by presenting a specially crafted Bluetooth peripheral. The vulnerability affects Chrome versions before 150.0.7871.47. While the technical severity is rated Medium, the practical risk is moderated by the requirement that an attacker must already have local network access and the ability to present a malicious Bluetooth device.

  • CVE-2026-14125MEDIUM 6.5

    A flaw in the ANGLE graphics library used by Google Chrome can leak sensitive data from a user's computer memory to an attacker through a malicious webpage. When a user visits a crafted HTML page, uninitialized memory containing potentially sensitive information becomes accessible, allowing the attacker to read data that should have been protected. The vulnerability requires user interaction—specifically visiting a malicious site—but no special privileges or complex setup are needed on the attacker's side.

  • CVE-2026-14146MEDIUM 6.5

    Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser processes CSS that could allow an attacker to trick users into visiting a malicious website and leak data from other websites the user has open. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require the attacker to have special privileges or bypass browser security features. While Chromium's security team rated this Low severity internally, the CVSS score reflects a Medium risk due to the potential for unauthorized information disclosure across security boundaries.

  • CVE-2026-14148MEDIUM 6.5

    A type confusion flaw in Google Chrome's CSS handling allows a remote attacker to trick a user into visiting a malicious webpage and potentially read sensitive data from the browser's process memory. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges. While Chromium rates the severity as low, the ability to leak memory contents elevates practical risk for targeted attacks.

  • CVE-2026-14155MEDIUM 6.5

    A flaw in Google Chrome's StorageAccessAPI—a mechanism that allows websites to request cross-origin data access—fails to enforce sufficient security policies. This permits an attacker to craft a malicious webpage that tricks users into leaking sensitive data from other websites. The vulnerability requires user interaction and is limited to information disclosure; it does not enable data modification or service disruption. Chrome versions prior to 150.0.7871.47 are affected.

  • CVE-2026-14156MEDIUM 6.5

    A flaw in Google Chrome's StorageAccessAPI allowed attackers who had already compromised the browser's rendering engine to bypass the same-origin policy—a core security boundary that prevents malicious websites from accessing data belonging to other sites. The attacker would need to trick a user into visiting a specially crafted webpage while the renderer process was already compromised. This vulnerability affects Chrome versions before 150.0.7871.47.

  • CVE-2026-14258MEDIUM 6.5

    dhcpcd, a widely used DHCP client daemon, contains a flaw in how it processes IPv6 Router Advertisement messages from the network. An attacker on the local network segment can send a specially crafted Router Advertisement packet with a zero-length option that bypasses validation checks. When the daemon attempts to reparse this malformed packet, it enters an infinite loop, consuming CPU resources until the process is manually stopped or the system is rebooted. This results in a denial-of-service condition affecting the target system's availability.

  • CVE-2026-14324MEDIUM 6.5

    A flaw in the RAOP (Remote Audio Output Protocol) module allows an attacker on the local network to cause a denial of service by sending requests with extremely large Content-Length values. The module fails to properly validate these values and does not check whether internal memory allocation operations succeed, leading to potential crashes or service unavailability.

  • CVE-2026-14381MEDIUM 6.5

    Google Chrome versions before 150.0.7871.46 contain a flaw in the WebAppInstalls security UI that allows attackers to deceive users through carefully crafted web pages. An attacker can make Chrome's security indicators or install prompts appear fake, potentially tricking users into installing malicious web applications or granting unintended permissions. The vulnerability requires user interaction to exploit but poses a real risk because users rely on Chrome's visual cues to make trust decisions.

  • CVE-2026-14384MEDIUM 6.5

    A memory safety flaw in Chrome's graphics rendering engine (ANGLE) allows attackers to read sensitive data across security boundaries on Windows systems. By serving a specially crafted webpage, an attacker can trick a user into visiting a malicious site and leak information that should remain private—such as data from other websites the user has open. The vulnerability requires user interaction (clicking or visiting a link) but does not require the attacker to be authenticated or have special privileges.

  • CVE-2026-14386MEDIUM 6.5

    A memory access vulnerability in Chrome's graphics rendering engine (ANGLE) allows attackers to read sensitive data from your browser's memory by tricking you into visiting a specially crafted webpage. The vulnerability affects Chrome versions before 150.0.7871.46 and requires user interaction—you must click or view malicious content for the attack to work. An attacker cannot execute code or crash your browser, but they could potentially steal passwords, tokens, or other sensitive information stored in memory.

  • CVE-2026-14388MEDIUM 6.5

    Google Chrome versions before 150.0.7871.46 contain a memory reading vulnerability in the ANGLE graphics library. A remote attacker can exploit this by serving a specially crafted HTML page to a user. If a user visits the malicious page, the attacker may extract sensitive information—such as passwords, encryption keys, or other data—from Chrome's process memory. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special privileges or configuration.

  • CVE-2026-14396MEDIUM 6.5

    A memory safety issue in the ANGLE graphics library used by Google Chrome allows attackers to read sensitive data across website boundaries. When a user visits a malicious webpage, an attacker can craft specific HTML content that triggers an out-of-bounds memory read. This flaw enables unauthorized access to data intended for other websites—a cross-origin information disclosure. The vulnerability requires user interaction (visiting a malicious page) but does not require any special browser configuration or credentials.

  • CVE-2026-14399MEDIUM 6.5

    A memory initialization flaw in Chrome's graphics rendering engine (Dawn) could allow an attacker to trick a user into visiting a specially crafted webpage that reads sensitive data from the browser's memory. The issue affects Chrome versions before 150.0.7871.46 and requires user interaction—the victim must click through or visit a malicious site—but does not require any special system privileges. Once exploited, an attacker gains read access to information already in memory, potentially including cached credentials, session tokens, or other sensitive data processed by the browser.

  • CVE-2026-14402MEDIUM 6.5

    A memory disclosure vulnerability in Google Chrome's ANGLE graphics library on Windows allows attackers to leak sensitive data from the browser process. An attacker can craft a malicious HTML page that, when visited by a user, reads uninitialized memory regions. While this does not allow code execution or system compromise, the leaked data could include passwords, session tokens, or other secrets resident in Chrome's memory space.

  • CVE-2026-14404MEDIUM 6.5

    A flaw in Google Chrome's PDF rendering engine (PDFium) allows attackers to trick users with misleading visual elements in specially crafted PDF files. When you open a malicious PDF, the attacker can manipulate what appears on screen to deceive you about the file's true content or origin—for example, making a phishing document look legitimate. The vulnerability affects Chrome versions before 150.0.7871.46 and requires user interaction (opening the PDF) to exploit.

  • CVE-2026-14408MEDIUM 6.5

    Google Chrome versions before 150.0.7871.46 contain a memory initialization flaw in Dawn (Chrome's graphics abstraction layer) that allows attackers to trick users into visiting malicious web pages and potentially read sensitive data from the browser process. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted website—but does not require special permissions or an authenticated account.

  • CVE-2026-14421MEDIUM 6.5

    A memory initialization flaw in Google Chrome's graphics library (Dawn) allows an attacker to trick users into visiting a malicious website that leaks sensitive data from the browser's memory. The vulnerability affects Chrome on ChromeOS systems prior to version 150.0.7871.46. While exploitation requires user interaction—clicking a link or visiting a crafted page—the flaw can expose information that might aid further attacks, such as cryptographic keys or session tokens. The impact is information disclosure only; the attacker cannot execute code or crash the system.

  • CVE-2026-14714MEDIUM 6.5

    A flaw in chatgpt-on-wechat (CowAgent) version 2.1.0 allows attackers to bypass authentication on the WeChat endpoint by manipulating or omitting a required security token. The vulnerable code fails to validate whether the token is actually present before attempting signature verification, meaning an empty or missing token can pass authentication checks. An attacker can exploit this remotely without credentials to interfere with message integrity or system availability.

  • CVE-2026-14792MEDIUM 6.5

    A security flaw in Formbricks 5.0.0 allows remote attackers to bypass access controls on survey-related functionality without requiring authentication. The vulnerability exists in the survey link handling component and can be exploited to modify data or disrupt availability. Upgrading to version 5.1.0-rc.1 or later resolves the issue.

  • CVE-2026-14803MEDIUM 6.5

    Mojo::JSON, a widely-used JSON parsing library for Perl, has a vulnerability in its pure-Perl decoder that allows attackers to consume excessive memory through deeply nested JSON structures. When a malicious or malformed JSON document with extreme nesting depth is parsed, the decoder recurses without limits, exhausting available memory and crashing the application. This affects only the pure-Perl fallback decoder; systems using the faster Cpanel::JSON::XS library are unaffected. Any Perl application that accepts JSON input from untrusted sources—such as HTTP request bodies—is vulnerable if Cpanel::JSON::XS is not installed or has been explicitly disabled.

  • CVE-2026-14898MEDIUM 6.5

    The OpenAI Codex desktop app for macOS has a vulnerability that allows attackers to steal sensitive information from users' sessions. An attacker can craft malicious prompts that trick the Codex model into generating URLs pointing to attacker-controlled servers. When the app displays the response, it automatically loads these remote images without requiring the user to click anything, causing the embedded sensitive data—like API keys or source code—to be sent to the attacker. This happens because the app renders Markdown-formatted responses and fetches remote images automatically.

  • CVE-2026-14904MEDIUM 6.5

    AWS Research and Engineering Studio (RES) contains a flaw that allows authenticated users to read any file on the cluster-manager server by exploiting how the system handles SSH key uploads. An attacker with valid credentials can replace their SSH private key with a symbolic link pointing to sensitive files elsewhere on the server. Because the cluster-manager process runs with root privileges, this exposes files that should be restricted, including other users' SSH keys and application secrets. This is a privilege-escalation risk that requires valid authentication to exploit, but once inside, the attacker gains broad file-read access they shouldn't have.

  • CVE-2026-1500MEDIUM 6.5

    GitLab CE and EE are vulnerable to a denial-of-service attack that can be triggered by authenticated users uploading specially crafted files. When an attacker sends a malicious file, the affected GitLab instance consumes excessive system resources (CPU, memory, disk I/O) without proper limits, potentially making the service unavailable to legitimate users. The vulnerability requires valid login credentials but no special user privileges to exploit.

  • CVE-2026-15104MEDIUM 6.5

    The BetterDocs plugin for WordPress—used to build internal documentation, knowledge bases, and FAQ systems—contains a SQL injection vulnerability in versions up to 4.6.0. An authenticated user with custom-level access or higher can manipulate a language parameter to inject malicious SQL commands and extract sensitive data from the site's database. The attack requires a supported multilingual plugin (WPML, Polylang, qTranslate, Weglot, or TranslatePress) to be active, which gates the vulnerable code path.

  • CVE-2026-15109MEDIUM 6.5

    A memory initialization flaw in ANGLE (the graphics abstraction layer used by Chrome) could allow an attacker to trick a user into visiting a malicious website that leaks sensitive data from the browser's memory. The vulnerability requires user interaction—a user must click a link or visit the page—but once there, the flaw enables reading uninitialized memory that may contain passwords, tokens, or other private information.

  • CVE-2026-15154MEDIUM 6.5

    A vulnerability in Red Hat OpenShift AI's guardrails-detectors component allows attackers to craft malicious regular expressions that trigger excessive processing on the system. When processed by the detection API, these expressions cause a worker process to consume all available CPU indefinitely, effectively freezing the LLM safeguard pipeline and preventing legitimate requests from being served.

  • CVE-2026-15192MEDIUM 6.5

    A missing authentication vulnerability exists in Mettle Sendportal's API webhook handlers for email service integrations (Sendgrid, Postmark, Postal, Mailjet). An unauthenticated attacker can remotely manipulate webhook functions, potentially allowing unauthorized interception or modification of email delivery notifications. The vulnerability affects versions up to and including 3.0.1, and public exploitation details are available.

  • CVE-2026-15287MEDIUM 6.5

    The rtMedia plugin for WordPress, which integrates with BuddyPress and bbPress, contains a SQL injection vulnerability in how it processes the order_by parameter. Attackers who have at minimum a subscriber-level WordPress account can manipulate this parameter to inject malicious SQL commands into database queries. This allows them to read sensitive data stored in the WordPress database without modifying or deleting it. The vulnerability affects all versions up to and including 4.6.18.

  • CVE-2026-1869MEDIUM 6.5

    A critical vulnerability in the popular User Registration & Membership WordPress plugin allows attackers to bypass payment processing and activate premium memberships without paying. The flaw exists in the payment confirmation function, which fails to validate user input properly. Any visitor to a site running the vulnerable plugin can exploit this to gain access to paid content and features, potentially causing revenue loss and unauthorized access to restricted materials.

  • CVE-2026-1871MEDIUM 6.5

    TP-Link Tapo C200 v5 camera firmware contains a flaw in how it validates incoming RTSP (Real Time Streaming Protocol) authentication requests. An attacker on the local network can send a specially crafted authentication message that overflows a memory buffer, crashing the camera's streaming service and forcing an automatic reboot. During this outage, users cannot view live video or manage the camera remotely. Once the camera restarts, service is restored, but the vulnerability remains exploitable, making repeated attacks feasible.

  • CVE-2026-22551MEDIUM 6.5

    Eclipse Theia, a browser-based IDE platform, contains a vulnerability in its AI chat feature that allows attackers to exfiltrate sensitive workspace data. When a user opens a malicious or compromised workspace and interacts with the AI chat, an attacker can inject prompts that trick the AI into generating Markdown image tags pointing to attacker-controlled servers. Because Theia automatically renders these images by fetching them from arbitrary URLs, the attacker can encode sensitive information—such as file contents, API keys, or conversation history—in the image URL itself, effectively stealing it. This requires user interaction (opening a workspace and using AI chat) but no special privileges. The risk is elevated in environments where developers regularly open workspaces from untrusted or semi-trusted sources.

  • CVE-2026-22899MEDIUM 6.5

    A NULL pointer dereference flaw in QNAP File Station 6 allows authenticated users to crash the service, causing a denial-of-service condition. An attacker must first obtain valid user credentials to exploit this vulnerability. The issue does not compromise confidentiality or integrity—only availability. QNAP has released a patch for File Station 5 version 5.5.6.5208 and later; however, the advisory indicates File Station 6 remains affected, and a specific patched version for File Station 6 has not yet been disclosed in available vendor guidance.

  • CVE-2026-23638MEDIUM 6.5

    Kiteworks, a platform designed to secure and control data sharing across organizations, contains a flaw that allows authenticated users to modify form approval workflows that belong to other users. The vulnerability stems from inadequate checks on who actually owns or has permission to modify a particular form's configuration. An attacker with valid Kiteworks credentials could exploit this to alter how forms route for approval, potentially disrupting legitimate business processes or gaining unauthorized visibility into sensitive approvals.

  • CVE-2026-2381MEDIUM 6.5

    The WooCommerce Stripe Payment Gateway plugin contains a flaw that allows attackers to sabotage pending orders without authentication. By exploiting a missing verification step, attackers can force orders into a failed state using a fake payment method. This attack works because the plugin only checks a security token that is publicly visible on WooCommerce checkout pages, and does not confirm the attacker actually owns or has permission to modify the order being targeted. Attackers can enumerate sequential order IDs to identify and attack multiple orders.

  • CVE-2026-24717MEDIUM 6.5

    A path traversal vulnerability in QNAP operating systems allows an attacker who already has administrator credentials to read files and system data they shouldn't have access to. While the attacker needs valid admin account access first, once obtained, they can bypass file access restrictions to view sensitive information. QNAP has released patched versions across multiple OS lines to fix this issue.

  • CVE-2026-24720MEDIUM 6.5

    File Station 6, a QNAP file management product, contains a resource exhaustion vulnerability that allows authenticated users to consume system resources without limits, potentially starving other applications and processes of critical resources. An attacker with valid credentials could trigger conditions that degrade or block access for legitimate users and services on the same system.

  • CVE-2026-24753MEDIUM 6.5

    Kiteworks Secure Data Forms contained an authorization flaw that allowed authenticated users to modify data forms and resources belonging to other users. The vulnerability stems from insufficient checks verifying that a user actually owns or has permission to modify a resource before allowing the action. Any authenticated user could exploit this by directly referencing another user's resource identifiers and making changes. This is categorized as an Insecure Direct Object Reference (IDOR) vulnerability. The issue is resolved in Kiteworks version 9.3.0 and later.

  • CVE-2026-2508MEDIUM 6.5

    The Gravity Forms Booking plugin for WordPress contains a SQL injection vulnerability affecting all versions up to 2.7.1. Attackers with Subscriber-level access or higher can inject malicious SQL commands through the 'staff_id' parameter to extract sensitive database information. The vulnerability requires authentication but poses a meaningful risk to sites that allow user registration or have internal staff accounts.

  • CVE-2026-25657MEDIUM 6.5

    Ericsson's Packet Core Gateway (PCG) has a vulnerability that allows an attacker on the local network to send specially crafted messages that crash or degrade the service. The good news: once the attacker stops, the system recovers automatically without manual intervention. This is a denial-of-service issue—it takes the service offline temporarily but doesn't steal data or give attackers permanent control. Organizations running PCG versions before 1.30 are at risk.

  • CVE-2026-25658MEDIUM 6.5

    Ericsson Packet Core Gateway versions before 1.30 contain a vulnerability where attackers can send specially crafted messages to degrade service availability. The system crashes repeatedly while the attack continues, but recovers automatically once the attacker stops. This is a network-based attack requiring no authentication or user interaction.

  • CVE-2026-25659MEDIUM 6.5

    Ericsson's Packet Core Gateway (PCG) has a vulnerability that allows attackers on the local network to degrade service by repeatedly sending specially crafted messages. The system becomes unresponsive while attacks continue, but recovers normally once the attacker stops. This is not a persistent damage vulnerability—it's a denial-of-service condition that requires active, ongoing attack traffic.

  • CVE-2026-26355MEDIUM 6.5

    Dell PowerProtect Data Domain contains a command injection flaw that allows attackers with high-level system access to execute arbitrary OS commands remotely. This vulnerability affects multiple release branches (standard, LTS2026, LTS2025, and LTS2024) across a range of versions. While the attacker must already possess elevated privileges, successful exploitation could lead to complete system compromise through command execution.

  • CVE-2026-26379MEDIUM 6.5

    Koha, an open-source library management system, contains a Server-Side Request Forgery (SSRF) vulnerability in its Z39.50/SRU server configuration. An authenticated attacker can exploit this flaw to scan the internal network and discover which services are running by measuring how the server responds to requests. This vulnerability affects Koha versions up to and including 25.11.

  • CVE-2026-2675MEDIUM 6.5

    RTI Connext Professional's security plugins contain a missing authentication check on a critical function, allowing an authenticated user to impersonate the source of data messages. This undermines the integrity of distributed data flows without requiring elevated privileges or user interaction. An attacker with valid credentials to the Connext system could inject falsified data that appears to originate from legitimate sources, potentially disrupting dependent applications that rely on data provenance.

  • CVE-2026-26824MEDIUM 6.5

    libxls, a widely-used library for reading Microsoft Excel files, has a memory safety issue that could allow an attacker to crash applications or potentially leak sensitive information. The vulnerability exists in how the library initializes internal data structures when parsing Excel file containers. An attacker who crafts a malicious Excel file and tricks a user or application into opening it could trigger the vulnerability. This is a moderate-severity issue affecting the library through version 1.6.3.

  • CVE-2026-27145MEDIUM 6.5

    Go's x509 certificate verification function contained a performance flaw where hostname validation was inefficient. When checking if a certificate's DNS Subject Alternative Names matched the requested hostname, the code repeatedly split the hostname string for each SAN entry rather than doing this work once. This created a quadratic performance problem: the cost grew exponentially with both the number of DNS SANs in the certificate and the number of labels (dot-separated parts) in the hostname itself. An attacker could craft a certificate with an extremely large SAN list to cause verification delays. Worse, this overhead occurred even when validating untrusted certificates, before the certificate chain was properly validated, making denial-of-service attacks feasible.

  • CVE-2026-27878MEDIUM 6.5

    A vulnerability in Grafana Tempo allows an authenticated user to crash the service by submitting a specially crafted TraceQL query with an extremely large exemplars hint parameter. The Tempo instance will attempt to allocate excessive memory to process the request, eventually running out of memory and becoming unavailable. This is a denial-of-service attack that requires valid credentials to execute.

  • CVE-2026-28979MEDIUM 6.5

    An out-of-bounds memory access vulnerability exists in Apple's Safari browser and related Apple operating systems. When a user visits a malicious website, the flaw can crash the affected application unexpectedly. The vulnerability stems from insufficient bounds checking when processing web content, allowing an attacker to read from or write to memory locations outside intended boundaries. No data theft or system compromise occurs; the impact is limited to denial of service through application crashes.

  • CVE-2026-30040MEDIUM 6.5

    FastStone Image Viewer version 8.3 contains a memory overflow vulnerability in its core image processing engine (FSViewer.exe) that can be triggered when opening a specially crafted JPEG 2000 file. An attacker can exploit this by distributing a malicious JP2 file that, when opened by a user, causes the application to execute arbitrary code with the privileges of the person running FastStone. This is a remote attack requiring no special permissions or user interaction beyond opening the file.

  • CVE-2026-3088MEDIUM 6.5

    A vulnerability in Netgear mesh router systems allows attackers on the local network to crash the router or knock it offline by sending specially designed requests. No password or authentication is required — the attacker simply needs network access. This is a denial-of-service flaw that can disrupt your home or office WiFi without leaving traditional evidence of intrusion.

  • CVE-2026-31016MEDIUM 6.5

    Squidex CMS versions 7.21.0 and earlier contain a Cross-Site Request Forgery (CSRF) flaw that allows an unauthenticated attacker to perform unauthorized actions on behalf of authenticated users. The vulnerability specifically targets the IdentityServer account profile endpoint, enabling privilege escalation. An attacker could trick a logged-in administrator or user into unknowingly executing malicious requests that modify account settings or elevate permissions.

  • CVE-2026-3173MEDIUM 6.5

    The Meta Field Block plugin for WordPress has a permission-checking flaw that lets Contributor-level users and above read sensitive data stored in WordPress metadata. An attacker with basic contributor access can specify any object ID and type—bypassing the plugin's validation—to retrieve private information like user details, customer billing addresses, or other metadata that WordPress site administrators expected to keep hidden. On sites running e-commerce or membership plugins, this can expose personally identifiable information at scale.

  • CVE-2026-31978MEDIUM 6.5

    motionEye, a web-based video surveillance interface, contains a path traversal vulnerability in its preview and movie API endpoints that allows authenticated users to read files they shouldn't access. An attacker with a basic motionEye account could exploit this to extract sensitive files such as system credentials, configuration files with passwords, SSH keys, and footage from other cameras. The vulnerability affects all versions before 0.44.0 and requires only user-level privileges to exploit—no special admin access is needed.

  • CVE-2026-3198MEDIUM 6.5

    MLflow 3.9.0, when deployed with basic authentication enabled, contains an authorization bypass affecting several gateway API endpoints. The application fails to properly verify user permissions before allowing access to sensitive operations that list gateway secrets, endpoints, and model definitions. This means any user who has logged in—even with minimal privileges—can view all gateway configuration data, including API keys and proprietary model information that should be restricted. The vulnerability is confined to the basic-auth deployment mode and affects information disclosure rather than data modification or system availability.

  • CVE-2026-32682MEDIUM 6.5

    NGINX Gateway Fabric can be crashed by an authenticated user who has permission to create or modify GRPCRoute resources. By submitting specially crafted GRPCRoute configurations that include certain backendRef filters, an attacker can force the control plane to shut down unexpectedly. This requires valid credentials and explicit permissions on the system, limiting but not eliminating the risk.

  • CVE-2026-32718MEDIUM 6.5

    Coolify, an open-source platform for managing servers, applications, and databases, contains an authorization flaw that allows read-only API tokens to perform state-changing operations. Specifically, an attacker with read-scoped credentials can validate cloud tokens and servers—operations that should require higher privileges. This circumvents the intended permission model and enables unauthorized modifications to infrastructure state. The vulnerability affects all versions prior to 4.0.0-beta.466.

  • CVE-2026-33464MEDIUM 6.5

    Kibana contains a denial-of-service vulnerability that allows low-privileged authenticated users to crash the service by sending an oversized request to an internal API. When exploited, Kibana becomes unresponsive to all users until manually restarted or the process recovers. This is a resource exhaustion attack that requires valid credentials but no special privileges.

  • CVE-2026-33582MEDIUM 6.5

    Apache Answer versions through 2.0.0 contain a vulnerability allowing authenticated users to upload specially crafted TIFF image files that trigger excessive memory consumption during processing, causing the server to crash. This is an availability issue that can disrupt service but does not compromise data confidentiality or integrity.

  • CVE-2026-33800MEDIUM 6.5

    Juniper Networks Junos OS on MX Series routers has a vulnerability that allows an attacker on the same network segment to crash the Forwarding Processing Card (FPC) by repeatedly triggering Micro-BFD session state changes. The vulnerability exploits the router's event processing queue, which becomes overwhelmed when sessions continuously flip between up and down states. This causes a watchdog timer to expire, forcing the FPC to crash and cutting off traffic. The attack requires network adjacency but no authentication, and affects specific hardware models in the MX lineup.

  • CVE-2026-33801MEDIUM 6.5

    A flaw in Juniper Networks' routing daemon allows an attacker already connected to a BGP neighbor to crash the routing system by sending a malformed network update. The attacker must be directly connected to the device (adjacent network access), but does not need to authenticate. When triggered, the routing daemon restarts, causing all routes to stop working temporarily until the system recovers. The impact is contained to the affected device—malicious routes are not forwarded downstream.

  • CVE-2026-33803MEDIUM 6.5

    A configuration flaw in Juniper Networks Junos OS Evolved exposes an internal process to the network that should remain isolated. An attacker can reach this process over the internet without authentication, potentially gathering limited device information and degrading performance by consuming CPU resources. The vulnerability affects multiple Junos OS Evolved release branches and requires a software update to resolve.

  • CVE-2026-34031MEDIUM 6.5

    Apache Answer versions through 2.0.0 contain a vulnerability in how they handle user-supplied image URLs for profile pictures. The application fails to properly validate these URLs, allowing attackers to inject arbitrary external image sources. When users load their profiles or view other users' profiles, their browsers make requests to attacker-controlled servers, enabling tracking, analytics collection, or other reconnaissance activities. This is not a direct data breach, but rather a mechanism for exposing user behavior and session information to external parties.

  • CVE-2026-34050MEDIUM 6.5

    Coolify is a popular open-source server and application management platform. A flaw in its Settings/Updates component allows any authenticated user—not just administrators—to view and potentially alter automatic update settings or force update checks. This access control gap was present before version 4.0.0-beta.471. While an attacker would need valid login credentials, the lack of role-based authorization on this sensitive functionality creates meaningful risk in multi-user environments.

  • CVE-2026-3462MEDIUM 6.5

    The Frisbii Pay plugin for WordPress has a critical authorization flaw that allows low-privilege users (Subscriber level and above) to upload malicious CSV files and alter sensitive payment and order data. An attacker with basic authenticated access can overwrite WooCommerce payment tokens and customer order information without needing administrative rights, potentially compromising transaction integrity and customer payment records.

  • CVE-2026-34905MEDIUM 6.5

    Apache Answer versions up to 2.0.0 contain a flaw where unlisted questions—content intended to be hidden from public view—can be discovered and read by any authenticated user through direct API calls. The vulnerability bypasses the access controls meant to keep these questions private, exposing not only the questions themselves but also their answers, comments, and revision history to users who should not have permission to see them.

  • CVE-2026-35049MEDIUM 6.5

    Wire iOS users running versions before 4.16.0 are vulnerable to a denial-of-service attack where a specially crafted message causes the app to crash immediately upon receipt, without any user action required. The crash persists across app restarts, trapping users in a crash loop until they manually clear the app's local data. This affects authenticated users only—the attacker must have messaging access to the target.

  • CVE-2026-35211MEDIUM 6.5

    OpenCTI, an open-source cyber threat intelligence platform, contains a vulnerability in its GraphQL API that allows authenticated users to inject computationally expensive script code. Any user with knowledge management permissions can craft malicious search queries that consume excessive CPU resources on the Elasticsearch backend, degrading performance for all users and potentially causing service unavailability. This is a denial-of-service vulnerability that requires valid credentials but no special privileges beyond standard KNOWLEDGE capability access.

  • CVE-2026-35261MEDIUM 6.5

    Oracle Access Manager contains an authentication bypass vulnerability that allows attackers to gain unauthorized access to sensitive data without providing valid credentials. An attacker on a network can exploit this flaw through HTTP requests to read, modify, or delete data within the application. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0, and requires no special privileges or user interaction to exploit.

  • CVE-2026-35673MEDIUM 6.5

    OpenClaw versions before 2026.4.29 contain a Server-Side Request Forgery (SSRF) policy bypass that allows authenticated users to circumvent network security controls. The vulnerability exists in browser debug and export functionality, where attackers can reuse previously-blocked tabs to access or export content that should remain restricted by private-network SSRF policies. This is a policy evasion technique rather than a direct network breach—the attacker must already have authenticated access to these routes, but can then leverage that access to reach otherwise-protected resources.

  • CVE-2026-35718MEDIUM 6.5

    VIVOTEK FD8136 network cameras running firmware version 0300a contain a path traversal vulnerability in their administrative media download function. An authenticated attacker can craft requests to the vulnerable endpoint to read files anywhere on the device, potentially exposing sensitive configuration data, credentials, or system files. This requires valid login credentials but does not require user interaction to exploit.

  • CVE-2026-36499MEDIUM 6.5

    Open vSwitch v3.6.90 contains a flaw that allows someone with write access to its configuration database to cause the software to allocate an unreasonably large number of worker threads. By requesting more threads than the system can handle, an attacker can exhaust memory and CPU resources, effectively shutting down the switch. The vulnerability requires existing database access, limiting the immediate threat surface, but represents a significant availability risk in environments where OVSDB write permissions are not tightly controlled.

  • CVE-2026-36604MEDIUM 6.5

    A Mercusys AC12G (EU) V1 router running firmware version AC12G(EU)_V1_200909 fails to validate the HTTP Host header in requests, creating an opening for DNS rebinding attacks. When an attacker controls a domain, they can redirect that domain to the router's internal IP address. The router's existing CORS misconfiguration (which already allows requests from any origin) amplifies this weakness, permitting the attacker to extract sensitive information from the router's web interface as if the request came from a trusted source. This vulnerability requires user interaction—typically visiting a malicious website—but does not require authentication.

  • CVE-2026-36605MEDIUM 6.5

    Mercusys AC12G (EU) V1 routers running firmware version AC12G(EU)_V1_200909 contain a denial-of-service vulnerability where an attacker on the local network can send a small number of specially crafted incomplete HTTP requests to crash the router. The device becomes unresponsive and requires a physical power cycle to restore function. This affects network availability for all connected devices.