Medium Vulnerabilities

14 advisories

CVE-2026-67279

Sep 5, 2026

Medium 6.9

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an...

Read Advisory

CVE-2026-66384

Aug 12, 2026

Medium 5.3

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions....

Read Advisory

CVE-2026-20316

Jul 29, 2026

Medium 5.3

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac...

Read Advisory

CVE-2026-20262

Jun 15, 2026

Medium 6.5

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an af...

Read Advisory

CVE-2026-7473

Jun 5, 2026

Medium 6.9

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is p...

Read Advisory

CVE-2026-48710

May 26, 2026

Medium 6.5

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorith...

Read Advisory

CVE-2026-34926

May 21, 2026

Medium 6.7

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents ...

Read Advisory

CVE-2026-9082

May 20, 2026

Medium 6.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.1...

Read Advisory

CVE-2026-32201

Apr 14, 2026

Medium 6.5

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-32202

Apr 14, 2026

Medium 4.3

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-20122

Feb 25, 2026

Medium 5.4

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the atta...

Read Advisory

CVE-2026-20133

Feb 25, 2026

Medium 6.5

A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file ...

Read Advisory

CVE-2025-68686

Feb 10, 2026

Medium 5.9

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, Fort...

Read Advisory

CVE-2025-48700

Jun 23, 2025

Medium 6.1

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaSc...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.