Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 110/1777
5.3
CVE-2026-45755

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.

5.3
CVE-2026-45754

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1

6.1
CVE-2026-45753

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until

5.4
CVE-2026-45072

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.

6.5
CVE-2026-45070

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

6.1
CVE-2026-45064

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until

5.9
CVE-2026-15712

A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tra

6.0
CVE-2026-58638

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

5.5
CVE-2026-58547

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges loc

6.5
CVE-2026-58546

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

5.5
CVE-2026-58545

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

6.3
CVE-2026-58543

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver

6.5
CVE-2026-58539

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58535

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58533

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.8
CVE-2026-58528

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat

6.5
CVE-2026-57982

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

6.3
CVE-2026-57973

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perfor

6.2
CVE-2026-57095

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate

5.5
CVE-2026-57085

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

5.5
CVE-2026-57084

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-57083

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informatio

5.9
CVE-2026-56649

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File Syst

5.5
CVE-2026-56195

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-56192

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-56184

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose i

5.5
CVE-2026-56178

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el

6.5
CVE-2026-56168

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

5.4
CVE-2026-56157

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

6.1
CVE-2026-55898

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

6.3
CVE-2026-55145

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authori

5.5
CVE-2026-55142

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55139

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55138

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

4.6
CVE-2026-55135

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

5.5
CVE-2026-55124

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose info

5.5
CVE-2026-55121

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55057

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

6.5
CVE-2026-55054

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-55051

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information

5.5
CVE-2026-55050

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55047

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55046

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55042

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55035

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

4.6
CVE-2026-55030

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

5.5
CVE-2026-55028

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55027

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

6.2
CVE-2026-55026

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55023

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started