Medium Severity CVEs Medium

3,831 documented vulnerabilities classified as medium severity.

Other levels: Critical High Low

Top Affected Vendors (Medium Severity)

All Medium CVEs

CVE-2026-24198
5.6 medium

NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive information to an unauthorized actor. A successful exploit of this vulnerability might lead to denial of servi

May 26, 2026
CVE-2026-24197
6.5 medium

NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnera

May 26, 2026
CVE-2026-24182
6.5 medium

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.

May 26, 2026
CVE-2025-33221
4.4 medium

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.

May 26, 2026
CVE-2026-9565
6.3 medium

A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handler. Executing a manipulation can lead to os command injection. The attack can be executed remotely. Th

May 26, 2026
CVE-2026-8852
6.2 medium

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.

Ibm Http Server May 26, 2026
CVE-2026-48905
6.1 medium

Lack of input filtering leads to an XSS vector in the HTML filter code.

Joomla Joomla\! May 26, 2026
CVE-2026-48903
6.1 medium

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

Joomla Joomla\! May 26, 2026
CVE-2026-48900
4.3 medium

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

Joomla Joomla\! May 26, 2026
CVE-2026-48693
5.5 medium

FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp line 159). The print_screen_contents_into_file() function (src/fastnetmon_logic.cpp line 2186) opens t

Pavel-Odintsov Fastnetmon May 26, 2026
CVE-2026-47728
4.3 medium

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one project could cause event processing in that project to use sour

May 26, 2026
CVE-2026-46431
4.3 medium

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless of the caller's Origin. Because EventSource does not preflight and does not send cookies, the wildcard is sufficient t

May 26, 2026
CVE-2026-46430
4.3 medium

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows, and utils.JoinHostPort("", ":5553") resolves to ":5553". Th

May 26, 2026
CVE-2026-44723
5.0 medium

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four jobs, each passing it as a CLI argument to the Python test script run_tests_model_g

Vowpalwabbit Vowpal Wabbit May 26, 2026
CVE-2026-44502
4.3 medium

Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. The original validation logic parsed webhook URLs with Python’s urllib.parse.urlparse, then sent the request with requests.post. For malf

May 26, 2026
CVE-2026-44314
4.3 medium

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into mediaManager.createFileStream(...). Unlike the generic

Traccar Traccar May 26, 2026
CVE-2026-35220
4.3 medium

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

Joomla Joomla\! May 26, 2026
CVE-2026-30895
6.1 medium

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Joomla Joomla\! May 26, 2026
CVE-2026-30894
6.1 medium

Lack of output escaping leads to a XSS vector in the content history component.

Joomla Joomla\! May 26, 2026
CVE-2026-25901
6.1 medium

Lack of output escaping leads to a XSS vector in the multilingual associations component.

Joomla Joomla\! May 26, 2026
CVE-2026-25900
6.1 medium

Lack of output escaping leads to a XSS vector in the feed modules.

Joomla Joomla\! May 26, 2026
CVE-2025-36221
5.3 medium

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

May 26, 2026
CVE-2025-36220
4.3 medium

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

May 26, 2026
CVE-2025-36148
5.4 medium

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the int

May 26, 2026