Medium Vulnerabilities

9 advisories

CVE-2026-20262

Jun 15, 2026

Medium (6.5)

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an af...

Read Advisory

CVE-2026-7473

Jun 5, 2026

Medium (6.9)

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is p...

Read Advisory

CVE-2026-34926

May 21, 2026

Medium (6.7)

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents ...

Read Advisory

CVE-2026-9082

May 20, 2026

Medium (6.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.1...

Read Advisory

CVE-2026-32201

Apr 14, 2026

Medium (6.5)

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-32202

Apr 14, 2026

Medium (4.3)

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-20122

Feb 25, 2026

Medium (5.4)

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the atta...

Read Advisory

CVE-2026-20133

Feb 25, 2026

Medium (6.5)

A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file ...

Read Advisory

CVE-2025-48700

Jun 23, 2025

Medium (6.1)

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaSc...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.