2026 · Medium

Medium-severity vulnerabilities disclosed in 2026

Medium-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.

1284 published vulnerabilities · page 5 of 13

  • CVE-2026-10878MEDIUM 6.3

    A command injection vulnerability has been discovered in D-Link DWR-M920 routers running firmware versions 1.1.50 and 1.1.70. An authenticated attacker can manipulate a parameter in the SMS management interface to inject and execute arbitrary system commands. This requires an existing login to the device but does not require user interaction once authenticated. Public exploits are now available, increasing the practical risk.

  • CVE-2026-11181MEDIUM 6.3

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the Media Session feature is implemented. An attacker can craft a malicious HTML page that, when visited by a user, bypasses the browser's same-origin policy—a fundamental security boundary that prevents websites from accessing data or functionality from other sites without permission. This could allow the attacker to read sensitive information, make unauthorized changes, or disrupt functionality within the context of other websites the user has open. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require any special browser configuration.

  • CVE-2026-11184MEDIUM 6.3

    Google Chrome versions before 149.0.7827.53 contain a flaw that allows attackers to bypass navigation controls through a specially crafted webpage. An attacker could craft a malicious HTML page that, when visited by a user, circumvents Chrome's built-in protections that normally restrict where the browser can navigate. This requires user interaction—the victim must visit the malicious page—but the barrier to exploitation is otherwise low. The vulnerability affects Chrome on Windows, macOS, and Linux systems.

  • CVE-2026-11187MEDIUM 6.3

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in the Glic component that allows an attacker to bypass navigation restrictions by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting the malicious page) and affects users across Windows, macOS, and Linux platforms. While the immediate impact is moderate, the ability to circumvent navigation safeguards could enable follow-on attacks or unauthorized content access.

  • CVE-2026-11308MEDIUM 6.3

    CVE-2026-11308 is a privilege escalation vulnerability in Google Chrome's extension system that allows an attacker to gain elevated permissions on a user's system. The attack requires social engineering—convincing a user to install a malicious browser extension—but once installed, the flaw in how Chrome enforces extension permissions allows the attacker to break out of the extension sandbox and perform actions at a higher privilege level than the extension should be allowed. This affects Windows, macOS, and Linux systems running Chrome versions prior to 149.0.7827.53.

  • CVE-2026-11333MEDIUM 6.3

    A file upload vulnerability exists in tittuvarghese CollegeManagementSystem that allows authenticated users to upload arbitrary files through the Student Data Upload endpoint. An attacker with login credentials can bypass upload restrictions by manipulating the Student-Data-CSV parameter, potentially introducing malicious files into the system. The vulnerability has been publicly disclosed and exploit code is available, though the project maintainers have not yet responded to the disclosure.

  • CVE-2026-11335MEDIUM 6.3

    A session fixation vulnerability has been discovered in tittuvarghese CollegeManagementSystem. An attacker can manipulate the UserAuthData parameter in the login form to hijack a user's session, potentially gaining unauthorized access to college management functions without requiring strong authentication. The vulnerability is remotely exploitable and does not require special access—any unauthenticated user can attempt the attack. Public exploit code is available, increasing the practical risk.

  • CVE-2026-11336MEDIUM 6.3

    A flaw in the College Management System allows authenticated users to bypass authorization controls and gain unauthorized access to sensitive administrative functions. An attacker with valid login credentials can manipulate a parameter called UserAuthData in the admin dashboard to perform actions they shouldn't be allowed to perform, potentially viewing, modifying, or deleting data. Because this vulnerability requires prior authentication and the exploit details are now public, it poses a meaningful security risk to organizations running this software.

  • CVE-2026-11339MEDIUM 6.3

    A command injection vulnerability exists in D-Link DWR-M920 routers up to firmware version 1.1.50. An authenticated attacker can inject arbitrary commands through the USSD Setup function, potentially gaining remote code execution on the device. The vulnerability requires valid login credentials but does not need user interaction to exploit. Public exploit code is now available.

  • CVE-2026-11341MEDIUM 6.3

    D-Link DWR-M920 routers up to firmware version 1.1.50 contain a command injection vulnerability in the IMEI setup form handler. An authenticated attacker can manipulate the IMEI_value parameter to execute arbitrary operating system commands on the affected device. The vulnerability requires valid login credentials but allows remote exploitation without user interaction once authenticated. Public exploit code has been released.

  • CVE-2026-11406MEDIUM 6.3

    GL.iNet MT3000 routers running firmware versions up to 4.4.5 contain a command injection flaw in the OpenVPN client import process. An authenticated user can craft a malicious OpenVPN configuration file that, when imported through the web interface, executes arbitrary system commands with the privileges of the router's web service. The vendor has released patched firmware that validates OpenVPN configuration files to block injection attempts.

  • CVE-2026-11408MEDIUM 6.3

    A remote code execution vulnerability exists in vertex-app versions up to 2026.02.12, where attackers with user-level access can inject arbitrary operating system commands through the Log Viewer endpoint. The flaw resides in how the application processes user-supplied query parameters without adequate sanitization, allowing an authenticated attacker to execute commands on the underlying server. Public exploit code is available, elevating practical risk despite the moderate CVSS score.

  • CVE-2026-11412MEDIUM 6.3

    Jinher OA C6 contains a SQL injection vulnerability in a web component that processes form identifiers. An attacker with login credentials can manipulate the queryID parameter in GetFormSyn.aspx to execute arbitrary database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is network-accessible and exploit code has been publicly released, increasing the risk of active exploitation.

  • CVE-2026-11438MEDIUM 6.3

    A security flaw in OneDev versions up to 15.0.5 allows authenticated users to manipulate project forking parameters in a way that bypasses authorization controls. An attacker with valid credentials can supply a crafted project ID in the forking mechanism to gain unauthorized access or modify projects they should not have permission to touch. This is a remote vulnerability requiring only standard user login—no special network access or user interaction needed beyond the attack itself.

  • CVE-2026-11439MEDIUM 6.3

    A vulnerability in OneDev up to version 15.0.5 allows authenticated users to manipulate parent project assignments in a way that bypasses authorization checks. An attacker with valid credentials can exploit the project.parentId parameter in the /projects/ endpoint to gain unauthorized access or make unauthorized changes to project hierarchies. This is a remote, network-accessible flaw that requires an existing user account to exploit.

  • CVE-2026-11440MEDIUM 6.3

    A vulnerability in OneDev versions up to 15.0.5 allows authenticated users to bypass authorization controls when modifying project default branch settings through the REST API. An attacker with login credentials can manipulate the `project.defaultBranch` parameter to gain unauthorized access or make changes they shouldn't be permitted to make. The vulnerability requires valid authentication to exploit but poses a moderate risk due to the potential for privilege escalation or unauthorized repository configuration changes.

  • CVE-2026-11441MEDIUM 6.3

    A flaw exists in theonedev onedev versions up to 15.0.5 that allows authenticated users to bypass authorization checks when accessing pull request issues. An attacker with valid credentials can manipulate how the system validates whether they have permission to view or modify specific issues, potentially gaining unauthorized access to sensitive project data. The vulnerability is straightforward to exploit once an attacker has credentials, and it requires only network access to the affected instance.

  • CVE-2026-11447MEDIUM 6.3

    A command injection vulnerability exists in GL.iNet's GL-MT3000 router firmware versions up to 4.4.5. The flaw is located in the MTK Backend component (iwinfo.so) and can be exploited by an authenticated remote attacker to inject arbitrary commands through the device parameter. This allows an attacker with valid credentials to execute unauthorized system commands. The vendor has released version 4.7 with global protections to intercept malicious injection attempts.

  • CVE-2026-11449MEDIUM 6.3

    GL.iNet has patched a command injection vulnerability affecting their GL-MT3000 router running firmware 4.4.5. An authenticated attacker could execute arbitrary commands through the LuCI JSON-RPC interface, potentially compromising the router and devices on its network. The vulnerability is addressed in firmware 4.8.1 and later, though newer versions (4.7.13+) mitigate it by excluding LuCI by default.

  • CVE-2026-11453MEDIUM 6.3

    Tiobon Employee Self-Service System versions up to 7.2 contain a SQL injection flaw in the blog search functionality accessible through the login endpoint. An authenticated attacker can manipulate search keywords to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials and has been publicly disclosed, though it is not currently tracked in the CISA Known Exploited Vulnerabilities catalog. The vendor has not acknowledged or addressed this issue despite early notification.

  • CVE-2026-11461MEDIUM 6.3

    NousResearch's hermes-agent contains a flaw that allows an authenticated user to bypass authorization checks by manipulating the 'Title' argument in the resume endpoint. An attacker with valid login credentials can access or modify information they shouldn't have permission to reach. The vulnerability affects versions up to 0.12.0, is remotely exploitable, and exploit details have been publicly disclosed.

  • CVE-2026-11470MEDIUM 6.3

    A path traversal vulnerability exists in the hsweb-framework file upload component that allows authenticated users to manipulate filenames and access files outside the intended upload directory. An attacker with valid credentials can exploit this flaw to read or write arbitrary files on the affected system by crafting malicious filename parameters. Public disclosure means this vulnerability has been shared in security communities, increasing the likelihood of active exploitation attempts.

  • CVE-2026-11473MEDIUM 6.3

    A SQL injection vulnerability exists in jflyfox jfinal_cms versions up to 5.1.0 that allows authenticated users to manipulate the orderBy parameter in the AdvicefeedbackController, potentially exposing or modifying database contents. The vulnerability requires valid login credentials but can be exploited over the network without user interaction once authenticated.

  • CVE-2026-11475MEDIUM 6.3

    A SQL injection vulnerability has been discovered in Kushan2k's student-management-system affecting the Certificate Verification Endpoint. An attacker with login credentials can manipulate the 'nic' parameter in the getStatus function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability is rated MEDIUM severity and exploits have been publicly disclosed, creating immediate risk for deployed instances.

  • CVE-2026-11476MEDIUM 6.3

    Kushan2k's student-management-system contains a flaw in its admin profile update endpoint that allows authenticated users to escalate their privileges by manipulating the 'isadmin' parameter. An attacker with legitimate credentials can modify this parameter to grant themselves administrative access without proper authorization checks. The vulnerability has already been disclosed publicly, and remote exploitation requires only network access and valid login credentials.

  • CVE-2026-11480MEDIUM 6.3

    A SQL injection vulnerability exists in BeikeShop, an e-commerce platform by Chengdu Everbrite Network Technology, affecting versions up to 1.6.0.22. An authenticated attacker can manipulate the 'settings.value' parameter in the Admin Design Builder endpoint to inject malicious SQL commands. The vulnerability requires login credentials but carries a network-based attack vector, allowing an attacker with admin or user-level access to read, modify, or delete database contents.

  • CVE-2026-11495MEDIUM 6.3

    CodeAstro Ingredients Stock Management System version 1.0 contains a SQL injection vulnerability in its stock addition functionality. An authenticated attacker can manipulate the ID parameter in the /Ingredients-Stock/add_stock.php file to execute arbitrary SQL queries. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid credentials to exploit but carries moderate severity due to its potential for data theft and integrity compromise.

  • CVE-2026-11506MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff deletion search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_for_deletion.php file to inject malicious SQL commands. This could allow unauthorized access to sensitive database information, modification of records, or disruption of the system. The vulnerability requires an authenticated login but poses a meaningful risk in environments where user accounts are shared or weak credential hygiene exists.

  • CVE-2026-11507MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Leave Management System version 1.0 that allows authenticated users to manipulate the leave_type parameter in the admin delete function, potentially extracting or modifying database information. The flaw requires valid login credentials but no additional user interaction, and public exploit code is available.

  • CVE-2026-11508MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff assignment search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_to_assign_pc.php file to inject malicious SQL commands. This allows remote exploitation without user interaction and poses a direct risk to database confidentiality, integrity, and availability. Public disclosure of this vulnerability means active exploitation is possible.

  • CVE-2026-11509MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff search functionality. An authenticated user can manipulate the Name parameter in the /admin/search_staff_for_updation.php file to inject arbitrary SQL commands, potentially reading or modifying sensitive employee and leave data. The vulnerability requires valid login credentials but poses a meaningful risk to organizations using this system, as it could enable unauthorized data access or manipulation by internal actors.

  • CVE-2026-11510MEDIUM 6.3

    CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its administrative interface. An authenticated attacker can manipulate the type_of_leave parameter when submitting leave requests through /admin/add_leave.php to inject malicious SQL commands. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid administrative credentials to exploit, but public exploit code is now available, increasing the practical risk.

  • CVE-2026-11513MEDIUM 6.3

    A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the adminaccount.php file. An authenticated attacker can manipulate the Date parameter to inject arbitrary SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires valid login credentials but can be exploited over the network. Public exploits are available.

  • CVE-2026-11514MEDIUM 6.3

    itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in the patient admission form. An authenticated attacker can manipulate the admission time parameter in the /addpatient.php file to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials but can be exploited remotely with no additional user interaction.

  • CVE-2026-11519MEDIUM 6.3

    SourceCodester Inventory System version 1.0 contains a privilege escalation vulnerability in its user account creation mechanism. An authenticated attacker can manipulate the ROLE parameter during account creation to bypass authorization controls and gain elevated privileges. The vulnerability requires valid login credentials but can be exploited remotely without user interaction. Public exploits are available, increasing the likelihood of active exploitation.

  • CVE-2026-11521MEDIUM 6.3

    A security vulnerability exists in the Transaction Endpoint of the Mohammed-eid35 bank-management-system-springboot project that allows authenticated users to perform actions they shouldn't be authorized for. The flaw lies in the TransactionController component and enables an attacker with valid login credentials to manipulate transaction data beyond their permitted scope. Because this is a publicly disclosed vulnerability affecting a banking system component, prompt remediation is important even though exploitation requires existing user access.

  • CVE-2026-11529MEDIUM 6.3

    A SQL injection vulnerability exists in the mysql-mcp-server component (versions up to 0.2.2) that allows authenticated users to execute arbitrary SQL commands by manipulating URI parameters. An attacker with valid credentials can read, modify, or delete database records. The vulnerability has been publicly disclosed, increasing immediate risk. Upgrading to version 0.3.0 eliminates the issue.

  • CVE-2026-11532MEDIUM 6.3

    A security flaw has been discovered in imvks786's student management system that weakens access controls on student records. An authenticated user with basic access can manipulate requests to the Student Record Handler component (/add.php) to gain unauthorized permissions or modify data they shouldn't be able to touch. The vulnerability requires login credentials but can be exploited remotely. Public disclosure of exploitation techniques has already occurred, increasing near-term risk.

  • CVE-2026-11558MEDIUM 6.3

    CodeAstro Payroll System version 1.0 contains a SQL injection vulnerability in the /home_salary.php file. An authenticated attacker can manipulate the rate or salary_rate parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete sensitive payroll data. The vulnerability requires a valid user login but can be exploited over the network without user interaction once authenticated.

  • CVE-2026-11559MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Payroll System version 1.0 that allows authenticated users to manipulate database queries through the ID parameter in the /view_account.php file. An attacker with valid credentials can inject malicious SQL commands to access, modify, or delete sensitive payroll data. The vulnerability is network-accessible and does not require additional user interaction, though authentication is required. Public exploits are now available, increasing the risk of active exploitation.

  • CVE-2026-11583MEDIUM 6.3

    CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in the class creation administrative function. An authenticated attacker can manipulate the className input parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid login credentials but can be exploited over the network without additional user interaction.

  • CVE-2026-11584MEDIUM 6.3

    A SQL injection vulnerability exists in CodeAstro Student Attendance Management System version 1.0 that allows authenticated users to manipulate a parameter in the class editing interface and execute arbitrary database commands. An attacker with login credentials can inject malicious SQL through the ID argument to read, modify, or delete sensitive student and attendance data. The vulnerability is network-accessible and exploit code has been publicly disclosed, increasing the practical attack surface.

  • CVE-2026-11585MEDIUM 6.3

    CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its class management functionality. An authenticated attacker can manipulate the classId parameter in the createClassArms.php file to inject malicious SQL commands, potentially allowing unauthorized access to or modification of the database. The vulnerability requires user authentication but can be exploited remotely without user interaction.

  • CVE-2026-11619MEDIUM 6.3

    A flaw exists in Dolibarr ERP CRM versions up to 23.0.2 within the Legacy Filemanager component. An authenticated attacker can exploit improper authorization controls in a configuration file to gain unauthorized access to functionality they should not have. The vulnerability allows remote exploitation and does not require user interaction. Public exploit code is available, increasing practical attack risk. The issue is resolved by upgrading to version 23.0.3 or later.

  • CVE-2026-21404MEDIUM 6.3

    NAVTOR NavBox versions up to 4.16.1.20 contain hard-coded credentials embedded in its SOAP (Windows Communication Foundation) implementation. When SOAP functionality is enabled, a local user with basic system access can extract these credentials, authenticate to the SOAP interface, and gain unauthorized access to privileged methods that allow arbitrary file write and overwrite operations on the system. This vulnerability requires local access to trigger but bypasses intended security workflows entirely.

  • CVE-2026-25599MEDIUM 6.3

    This vulnerability affects Orca heat pump devices and their control portal. An attacker can intercept unencrypted communications between older Orca heat pumps and the control server, impersonate a legitimate device, and inject malicious code into the web portal. This injected code can steal user session cookies, compromise accounts, expose sensitive information, and grant attackers unauthorized access to the portal. The core issues are the lack of authentication, unencrypted HTTP connections, and missing input validation.

  • CVE-2026-35716MEDIUM 6.3

    A stack-based buffer overflow vulnerability exists in VIVOTEK FD8136 IP cameras that allows an authenticated attacker to run arbitrary code with root privileges. The flaw is in the motion privacy configuration endpoint, which fails to validate the size of user input before copying it into a fixed-size buffer on the stack. Because the camera firmware lacks stack protection mechanisms, an attacker can overwrite return addresses and hijack program execution. An authenticated attacker on the network can exploit this remotely by sending a specially crafted POST request.

  • CVE-2026-35717MEDIUM 6.3

    A stack-based buffer overflow exists in the export_language.cgi binary on VIVOTEK FD8136 IP cameras running firmware FD8136-VVTK-0300a. An authenticated attacker can send a specially crafted POST request to the language export endpoint with a malicious Content-Length value that causes the application to read more data than a 60-byte stack buffer can hold, overwriting critical return address information. This allows the attacker to execute arbitrary code with root privileges on the affected device. The vulnerability requires valid credentials to exploit but succeeds because the binary lacks stack protection mechanisms.

  • CVE-2026-39107MEDIUM 6.3

    Kimi AI v1.0 has a cross-site scripting (XSS) vulnerability in its Preview feature. When the AI generates code and displays it in the Preview tab, the application fails to sanitize the output properly. An attacker can embed malicious JavaScript in AI-generated responses, which then executes in a user's browser with the privileges of that session. This could allow theft of session cookies, unauthorized actions on behalf of the user, or credential harvesting.

  • CVE-2026-41975MEDIUM 6.3

    CVE-2026-41975 is a permission management flaw in a network management module that could allow a local attacker with limited privileges to compromise service integrity. The vulnerability requires user interaction and specific system conditions to exploit, making it a moderate-risk issue that organizations should address but not treat as an emergency.

  • CVE-2026-42538MEDIUM 6.3

    IRIS is a collaborative platform designed to help incident responders coordinate during security investigations by sharing technical findings. A file validation flaw in versions before 2.4.28 allows authenticated users to upload files without proper checks. This can enable attackers to host malicious content—such as phishing pages—directly within the platform, and also introduces a Cross-Site Scripting (XSS) vulnerability that could compromise other users' sessions or steal credentials when they interact with uploaded files.

  • CVE-2026-44287MEDIUM 6.3

    FastGPT, an AI Agent building platform, contains a sandbox escape vulnerability in versions before 4.15.0-beta1. The issue stems from an incomplete regex filter designed to block dynamic imports in a JavaScript sandbox environment. An attacker with valid platform access can craft a specially formatted import statement using block comments to bypass the filter, gaining the ability to execute arbitrary system commands within the sandbox container. This allows an authenticated user to break out of the intended sandbox isolation and run code with the permissions of the sandbox process.

  • CVE-2026-45157MEDIUM 6.3

    A vulnerability in Nextcloud Server allows a malicious user who has been granted access to a shared file to bypass intended restrictions and view temporary upload files during an ongoing chunked file transfer. The attacker leverages the share token—credentials normally intended only for accessing the shared file—to gain unauthorized access to the file upload staging area. This exposure occurs across specific versions of both the open-source Nextcloud Server and Nextcloud Enterprise Server.

  • CVE-2026-45283MEDIUM 6.3

    Nextcloud Server contains a file access control vulnerability in its files_lock app that allows authenticated users to manipulate file locks belonging to other users. By knowing the WebDAV paths of files owned by colleagues, an attacker could lock or unlock those files without authorization. Additionally, the vulnerability exposes lock tokens in error messages, enabling attackers to remove locks that other users' applications have legitimately placed. This requires an attacker to be a registered user with valid credentials, but does not require special privileges. The issue affects Nextcloud Server versions 32.0.0 through 32.0.1 and 33.0.0 through 33.0.0, with enterprise deployments on version 31 also at risk.

  • CVE-2026-45626MEDIUM 6.3

    Arcane, a Docker management interface, contains a command injection vulnerability in its volume browsing feature. When authenticated users request to browse files within a Docker volume, the application constructs a shell command that includes user-supplied path input. Although the application attempts to block directory traversal attacks using `../`, it fails to remove shell metacharacters like `$()` and backticks. This oversight allows an attacker to inject arbitrary commands that execute within the Arcane helper container. The results of injected commands are returned in error messages, effectively giving attackers a channel to execute code and exfiltrate output.

  • CVE-2026-46416MEDIUM 6.3

    Microsoft UFO, an open-source intelligent automation framework, has a flaw in how it manages WebSocket connections used for remote automation across devices and platforms. The vulnerability stems from improper reuse of a shared connection handler that processes authenticated user requests. When multiple users connect simultaneously, their connection contexts get mixed up—specifically, responses intended for one user can be delivered to another user who connected most recently. This allows an authenticated attacker to intercept and view responses that were meant for a different authenticated session, potentially exposing sensitive automation results or command outputs.

  • CVE-2026-49093MEDIUM 6.3

    CVE-2026-49093 is a Server-Side Request Forgery (SSRF) vulnerability in Kibana that allows authenticated users with connector management privileges to circumvent network egress controls. An attacker with these privileges can craft malicious connector configurations that cause the Kibana server to make outbound requests to internal or otherwise-blocked destinations, defeating the intent of operator-configured allowlists. This requires authentication and specific administrative permissions, but poses a meaningful risk to organizations using Kibana connectors for alerting, webhooks, or integrations.

  • CVE-2026-49943MEDIUM 6.3

    CZ.NIC BIRD Internet Routing Daemon versions up to 2.19.0 contain a stack-based buffer overflow vulnerability in its BGP AS_PATH filtering logic. When BIRD processes BGP UPDATE messages containing exceptionally long AS_PATH attributes—particularly when RFC 8654 Extended Messages are enabled—a mismatch between the fixed buffer size and the actual incoming data can cause the daemon to crash. An authenticated BGP peer can trigger this by sending a specially crafted UPDATE with an AS_PATH longer than what the code expects, leading to denial of service of the routing daemon.

  • CVE-2026-5066MEDIUM 6.3

    A vulnerability exists in Zephyr's TLS socket implementation where attackers with network access and authenticated credentials can trigger an out-of-bounds memory access. When TLS session caching is enabled, the system copies network address data into a fixed buffer without checking if the caller-supplied size matches the actual buffer capacity. An attacker can specify an artificially large address size, causing the copy operation to overwrite adjacent memory. This can crash the system, disrupt network services, or potentially allow code execution if memory corruption is leveraged effectively.

  • CVE-2026-5589MEDIUM 6.3

    A flaw in Zephyr's Bluetooth Mesh implementation allows a nearby attacker to send a malicious wireless advertisement that triggers memory corruption. The vulnerable code fails to validate that certain length values are reasonable before using them in calculations, leading to reads and writes far outside intended memory boundaries. Devices with Bluetooth Mesh enabled and the optional proxy server feature active are at risk. No authentication or pairing is required—an attacker simply broadcasts a specially crafted BLE packet.

  • CVE-2026-7299MEDIUM 6.3

    Appsmith, a low-code application development platform, contains a stored cross-site scripting (XSS) vulnerability in its SQL query editor. An authenticated developer can craft malicious database object names (table or column names) that, when rendered by the autocomplete feature, inject and execute arbitrary JavaScript in the browsers of other workspace members. This is a *persistence* risk—the malicious payload lives in the database schema itself and activates whenever a colleague accesses the same data source, potentially compromising their sessions and Appsmith workspace access.

  • CVE-2026-9831MEDIUM 6.3

    A timing vulnerability in Extreme Platform ONE's identity and access management (IAM) gateway could occasionally allow an authenticated user to view data belonging to a different customer organization. The issue occurs only under specific high-traffic conditions where concurrent API requests overlap, and only affects API-key-based authentication—not Extreme's newer token or OAuth methods. An attacker would need valid API credentials to attempt this, and success is not guaranteed; the flaw is triggered by race conditions in how the gateway validates which tenant's data should be returned.

  • CVE-2026-9989MEDIUM 6.3

    Google Chrome contained a flaw in how it handles media files that allowed attackers to bypass the same-origin policy—a critical browser security boundary. An attacker could craft a malicious video file that, when opened by a user in Chrome, would enable unauthorized access to sensitive data from other websites the user was visiting. The vulnerability requires user interaction (clicking a link or opening a file) but does not require special privileges or complex attack setup.

  • CVE-2016-20064MEDIUM 6.2

    WP Vault version 0.8.6.6 contains a local file inclusion (LFI) vulnerability that allows unauthenticated attackers to read arbitrary files from the server. An attacker can manipulate the wpv-image GET parameter to include directory traversal sequences (such as ../../../etc/passwd) and access sensitive files including system configuration files, credentials, and other protected data. No user authentication is required to exploit this vulnerability.

  • CVE-2018-25423MEDIUM 6.2

    Arm Whois version 3.11 has a buffer overflow flaw that allows local users to crash the application by entering an extremely long string into IP address or domain input fields. An attacker with local access can supply a malicious 700-byte input to trigger a denial of service, making the tool temporarily unavailable but without risking data theft or system compromise.

  • CVE-2022-50953MEDIUM 6.2

    The admin-word-count-column WordPress plugin version 2.2 contains a flaw that lets unauthenticated attackers read files they shouldn't be able to access. An attacker can craft a specially formed web request to the plugin's download-csv.php file, using directory-traversal tricks and null-byte injection to bypass the plugin's file-access controls. This allows them to download sensitive configuration files and other data directly from the server.

  • CVE-2026-0046MEDIUM 6.2

    CVE-2026-0046 is a local privilege escalation vulnerability affecting Google Android that exploits a weakness in the InputInterceptor component of Letterbox.java. An attacker can overlay malicious UI elements on top of legitimate permission prompts, tricking users into granting permissions they did not intend to approve. What makes this particularly concerning is that exploitation requires no special system privileges and occurs without user awareness—the victim merely sees what appears to be a normal permission dialog. The result is unauthorized elevation of the attacker's application privileges within the Android system.

  • CVE-2026-0055MEDIUM 6.2

    A path traversal vulnerability in Android's PackageInstallerService allows an attacker to write a Device Policy Controller (DPC) application to an unintended directory. By exploiting this flaw, an unprivileged local process can escalate its privileges without requiring user interaction or additional system permissions. The vulnerability affects multiple Android versions and could allow an attacker with local access to gain elevated capabilities on the device.

  • CVE-2026-42771MEDIUM 6.2

    CVE-2026-42771 is a vulnerability in OpenSSL's email address validation logic that can cause an application to crash when processing crafted email addresses. The flaw lies in how OpenSSL validates the local part (the part before the '@' symbol) of email addresses, particularly during S/MIME message validation. An attacker who can supply a malicious email address in an S/MIME message can trigger an out-of-bounds read that most likely results in a denial of service. The vulnerability does not allow data theft or system compromise beyond availability impact.

  • CVE-2026-45491MEDIUM 6.2

    A flaw in .NET's file handling allows an attacker with local access to manipulate files through improper link resolution. The vulnerability stems from the system failing to properly validate symbolic links or similar path references before opening files, which means an attacker could redirect file operations to unintended targets. While this requires local access and does not compromise confidentiality, it can lead to unauthorized modification of sensitive data or system files.

  • CVE-2026-8594MEDIUM 6.2

    Text::LineFold, a Perl module for handling line breaks in text, contains a bug that causes it to duplicate output when processing strings with certain special break characters (like vertical tabs and form feeds). The module splits input by these characters but then applies its line-breaking logic to the entire original string instead of just the individual segments, resulting in unnecessary duplication. While primarily a logic error, this can cause excessive memory and CPU consumption if exploited, potentially leading to denial of service on systems processing untrusted text input.

  • CVE-2019-25731MEDIUM 6.1

    Zuz Music version 2.1 has a flaw that lets anyone send malicious code through the contact form without needing to log in. When site administrators read these messages, the injected code runs in their browsers, potentially allowing attackers to steal session data, modify settings, or trick them into performing unwanted actions. This is a persistent vulnerability, meaning the malicious payload stays stored on the server and affects every admin who views the inbox.

  • CVE-2019-25737MEDIUM 6.1

    Live Chat Unlimited version 2.8.3 contains a stored cross-site scripting (XSS) vulnerability in its chat input field. An unauthenticated attacker can inject malicious JavaScript code that persists in the system and executes when administrators access the chat interface. This allows attackers to steal admin session cookies, redirect users to phishing sites, or perform unauthorized actions within the admin dashboard without requiring authentication.

  • CVE-2025-40808MEDIUM 6.1

    Siemens SIPROTEC 5 protective relays contain a file upload vulnerability affecting dozens of device models across multiple control processor variants. An authenticated attacker can upload malicious configuration files through the DIGSI 5 protocol, potentially disrupting power system operations or executing unauthorized code. The vulnerability requires valid credentials but represents a meaningful risk in environments where multiple operators or contractors have access to device management interfaces.

  • CVE-2026-10305MEDIUM 6.1

    Samsung's rlottie animation library contains a vulnerability that allows reading data beyond the intended buffer boundaries. When processing specially crafted animation files, the library may access memory it shouldn't, potentially exposing sensitive information or causing the application to crash. The issue stems from insufficient bounds checking during buffer operations. While the vulnerability requires user interaction (opening a malicious animation file) and is limited to local access, the combination of integrity impact and high availability risk warrants prompt attention.

  • CVE-2026-10510MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability exists in the GeniexWebView component of Transsion's AI Assistant Lifestyle application for Android. An attacker can craft a malicious URL containing injected JavaScript code in the web_action_data parameter, which the vulnerable WebView will execute with the same privileges as the application. This allows arbitrary JavaScript execution in the context of the app, potentially compromising user data or enabling phishing attacks. The vulnerability affects all versions of the application currently in distribution.

  • CVE-2026-10856MEDIUM 6.1

    MISP dashboard widgets contain a URL validation flaw that allows attackers to craft malicious buttons appearing to link within the application while actually redirecting users to external sites. The vulnerability stems from incomplete validation that accepts paths like '/\example.com', which browsers may normalize into scheme-relative URLs pointing to attacker-controlled domains. An attacker with dashboard configuration access can embed these crafted buttons to redirect legitimate users, creating phishing and credential-theft opportunities.

  • CVE-2026-10861MEDIUM 6.1

    MISP, a widely-used threat intelligence sharing platform, contains an open redirect vulnerability in its post-login redirect logic. When a user logs in, the application redirects them to a URL stored in the session without properly validating that the destination is actually part of the MISP application. An attacker can craft a malicious link that tricks users into visiting their legitimate MISP instance, then redirects them to an attacker-controlled website after they authenticate. This could be weaponized for phishing by appearing to come from a trusted source or to deliver malware from a domain the victim might not otherwise visit.

  • CVE-2026-10916MEDIUM 6.1

    CVE-2026-10916 is a cross-site scripting vulnerability in Google Chrome's developer tools that allows an attacker to inject malicious scripts or HTML content into a webpage. The attack requires two conditions: first, the attacker must have already compromised Chrome's renderer process (the component that executes web content), and second, the user must be tricked into visiting a specially crafted HTML page. While the initial compromise is a significant prerequisite, once achieved, this vulnerability enables the attacker to execute arbitrary code with the privileges of the browser session, potentially stealing sensitive data or performing actions on behalf of the user.

  • CVE-2026-11034MEDIUM 6.1

    Google Chrome on Android contains a vulnerability in its Tab Group Sync feature that allows attackers to inject malicious scripts or HTML into web pages. An attacker with network access can craft malicious traffic to exploit insufficient input validation, potentially displaying fake content or stealing user information from websites. This affects Chrome versions prior to 149.0.7827.53.

  • CVE-2026-11122MEDIUM 6.1

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the keyboard input handler processes certain HTML page elements. An attacker can craft a malicious webpage that, when visited by an unsuspecting user, injects arbitrary scripts or HTML content that executes in a security context where it shouldn't be allowed—a technique called Uniform Cross-Site Scripting (UXSS). This bypasses the browser's same-origin policy protections that normally prevent cross-domain attacks. The vulnerability requires user interaction (clicking or viewing the page) but affects all major platforms where Chrome runs.

  • CVE-2026-11150MEDIUM 6.1

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious webpage that, when visited, injects arbitrary scripts or HTML content that execute in the context of unrelated sites (a technique known as Universal Cross-Site Scripting or UXSS). This bypasses the same-origin policy that normally prevents one site from accessing data or performing actions on another. The vulnerability requires user interaction—a victim must visit the attacker's page—but does not require any special browser configuration or user privileges to trigger.

  • CVE-2026-11186MEDIUM 6.1

    Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in CSS handling that allows attackers to inject malicious scripts or HTML into web pages users visit. An attacker would craft a specially designed webpage that, when opened in a vulnerable version of Chrome, bypasses security boundaries and executes unauthorized code in the context of other websites. This type of attack, known as Universal XSS (UXSS), is particularly dangerous because it affects the browser itself rather than individual websites, potentially compromising user data across multiple domains.

  • CVE-2026-11205MEDIUM 6.1

    Google Chrome on iOS versions prior to 149.0.7827.53 contain a vulnerability that allows attackers to inject malicious scripts or HTML into web pages through crafted QR codes. The attack requires user interaction—specifically, the victim must engage with certain UI gestures in response to the attacker's QR code—but once triggered, the injected content runs with the privileges of the page being viewed. This is a cross-origin scripting (UXSS) issue, meaning the injected code can affect pages from different origins, potentially stealing session cookies, credentials, or sensitive data.

  • CVE-2026-11229MEDIUM 6.1

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the application handles certain enterprise features that could allow someone with physical access to your device to gain elevated privileges. The vulnerability requires an attacker to be present at the machine itself and does not need you to take any action—they can exploit it directly. This is a local-only threat and cannot be exploited remotely over the internet.

  • CVE-2026-11273MEDIUM 6.1

    Google Chrome versions before 149.0.7827.53 contain a vulnerability in the Omnibox (the address/search bar) that fails to properly validate user input. An attacker can craft a malicious HTML page that, when visited by a user who interacts with the Omnibox through specific UI actions, allows injection of arbitrary scripts or HTML content. This is a cross-site scripting variant (UXSS) that bypasses the normal security boundary between web pages. The attack requires user interaction and social engineering to be effective, but once triggered, can compromise the integrity and confidentiality of the browsing session.

  • CVE-2026-11603MEDIUM 6.1

    A reflected cross-site scripting (XSS) vulnerability exists in the Product Filter Widget for Elementor WordPress plugin through version 1.0.6. An attacker can craft a malicious link and trick a user into clicking it, causing arbitrary JavaScript to execute in the victim's browser within the context of their WordPress site. The vulnerability stems from the plugin's failure to properly sanitize user input in the 'args[filterFormArray]' parameter before displaying it back to the user. No authentication is required to exploit this flaw, and the attack is delivered silently via an admin-ajax.php endpoint without requiring verification that the request is legitimate.

  • CVE-2026-1450MEDIUM 6.1

    The rognone WordPress plugin contains a reflected cross-site scripting (XSS) flaw that allows unauthenticated attackers to inject malicious scripts into web pages. The vulnerability exists in how the plugin handles the 'mode' parameter—it fails to properly sanitize user input and escape output, creating an opening for attackers to craft malicious links. If a user clicks such a link while using a site running the vulnerable plugin, the attacker's script executes in their browser with access to session data and sensitive information.

  • CVE-2026-1451MEDIUM 6.1

    The rognone plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into pages viewed by unsuspecting users. An attacker could craft a malicious link containing JavaScript in the 'a' parameter and trick a user into clicking it, causing the script to execute in their browser within the context of the WordPress site. This works because the plugin fails to properly sanitize user input or escape output before displaying it. The vulnerability affects versions up to and including 0.6.2.

  • CVE-2026-20175MEDIUM 6.1

    A remote attacker can trick a user into clicking a malicious link that causes their browser to load files from an attacker-controlled location while interacting with Cisco Finesse. Because the application doesn't properly validate where those files come from, an attacker can inject malicious scripts or steal sensitive information visible in the user's active session—all without needing to authenticate first.

  • CVE-2026-20233MEDIUM 6.1

    Cisco Webex Meetings contained a cross-site scripting (XSS) vulnerability in its web interface that could allow an attacker to inject malicious scripts if a user clicked a crafted link. The vulnerability resulted from weak input validation. Cisco has already patched the service, and users do not need to take action—the fix has been deployed automatically.

  • CVE-2026-21825MEDIUM 6.1

    HCL Digital Experience and Digital Experience Compose contain a reflected cross-site scripting (XSS) vulnerability in their search center functionality. An attacker can craft a malicious link containing JavaScript code and trick a user into clicking it. When the victim visits the link, the attacker's script executes in their browser with their privileges, potentially stealing session cookies, credentials, or performing actions on their behalf. This vulnerability requires user interaction—the victim must click a malicious link—which somewhat limits its reach, but the ability to target any user makes it a meaningful risk for organizations relying on these platforms.

  • CVE-2026-21826MEDIUM 6.1

    HCL Digital Experience and HCL Digital Experience Compose contain a host header injection vulnerability that allows an attacker to manipulate how the application processes the Host header in HTTP requests. By injecting a malicious Host value, an attacker can trigger unexpected application behavior, potentially leading to phishing attacks, cache poisoning, or credential theft. The vulnerability requires user interaction—such as clicking a malicious link—to be exploited, which moderates the overall risk profile.

  • CVE-2026-2425MEDIUM 6.1

    The hiWeb Migration Simple WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability in how it handles the 'new_domain' parameter. An attacker can craft a malicious link and trick a WordPress administrator into clicking it, causing arbitrary JavaScript to execute in the admin's browser session. This could allow the attacker to steal session tokens, modify site content, or perform administrative actions on behalf of the compromised admin. The vulnerability affects all versions through 2.0.0.1.

  • CVE-2026-25688MEDIUM 6.1

    Apache Answer versions through 2.0.0 contain a cross-site scripting (XSS) vulnerability in how AI-generated response content is displayed to users. When Answer generates responses using AI, the application fails to properly clean this content before showing it in the browser. This allows an attacker to inject malicious scripts that execute in a user's browser when they view the generated response. The vulnerability requires user interaction (clicking a link or viewing a page with the malicious content) but can affect multiple users if the generated response is shared or cached.

  • CVE-2026-25699MEDIUM 6.1

    Apache Answer versions up to 2.0.0 contain an authorization bypass in timeline-related APIs that allows any authenticated user to view content they shouldn't have access to—including deleted items, private submissions, and unapproved materials, along with their full revision history. An attacker with a regular user account can exploit this by directly calling these APIs without needing elevated privileges. The vendor has released version 2.0.1 to address the flaw.

  • CVE-2026-29170MEDIUM 6.1

    Apache HTTP Server versions 2.4.67 and earlier contain a cross-site scripting (XSS) vulnerability in the mod_proxy_ftp module. When the server is configured to proxy FTP directory listings—whether forwarding traffic to an upstream FTP server or presenting one via reverse proxy—it fails to properly sanitize HTML generated for directory contents. An attacker can craft malicious FTP directory entries or filenames containing JavaScript code. When an administrator or user views the directory listing in a browser, the malicious script executes in their session, potentially allowing session hijacking, credential theft, or administrative actions.

  • CVE-2026-30586MEDIUM 6.1

    A cross-site scripting (XSS) vulnerability exists in usememos Memos version 0.26.0 that allows an attacker to inject malicious code into memo pages. When a user views a compromised memo—whether public or private—the attacker's script executes in the user's browser, potentially exposing sensitive information. The vulnerability stems from improper sanitization of user input in the memo rendering component, meaning the application fails to adequately strip or encode dangerous HTML and JavaScript before displaying memo content.

  • CVE-2026-33553MEDIUM 6.1

    Northern.tech CFEngine Enterprise contains a cross-site scripting (XSS) vulnerability in versions 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1. An attacker can inject malicious scripts that execute in the browser context of users interacting with the CFEngine Enterprise interface, potentially compromising user sessions or stealing sensitive information without requiring authentication.

  • CVE-2026-35212MEDIUM 6.1

    OpenCTI, an open-source threat intelligence platform, contains a cross-site scripting (XSS) vulnerability in how it renders email message data. An attacker can craft a malicious email observable with unsanitized content in the message body, which executes JavaScript in a victim's browser when they view it. Because threat intelligence is often shared across teams via STIX files or automated ingesters, this could be weaponized to steal session cookies at scale, potentially compromising multiple analysts' accounts. The vulnerability requires user interaction—someone must view the crafted email observable—but the attack surface is broad given how threat intelligence is typically distributed.