Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 112/1777
4.7
CVE-2026-50312

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

4.7
CVE-2026-50310

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information

4.2
CVE-2026-50302

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security f

6.4
CVE-2026-4018

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local acce

5.5
CVE-2026-49177

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

5.5
CVE-2026-48580

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-47969

Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attack

6.1
CVE-2026-45066

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until

6.1
CVE-2026-45065

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

4.3
CVE-2026-15715

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i

6.2
CVE-2026-0515

Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a cra

6.5
CVE-2026-59888

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From

5.5
CVE-2026-58614

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

6.5
CVE-2026-58279

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

6.5
CVE-2026-57979

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-57976

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ

6.4
CVE-2026-57097

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical atta

6.5
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

5.3
CVE-2026-56164 KEV

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate p

6.5
CVE-2026-55003

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.4
CVE-2026-55000

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

5.5
CVE-2026-54997

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

6.1
CVE-2026-54988

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

4.7
CVE-2026-54432

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus

6.8
CVE-2026-54132

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attac

6.5
CVE-2026-54108

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing o

6.6
CVE-2026-50678

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-50381

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized

5.5
CVE-2026-50350

Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authori

5.5
CVE-2026-50316

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information

5.5
CVE-2026-50303

Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypas

5.5
CVE-2026-50300

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

6.8
CVE-2026-50299

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a p

6.8
CVE-2026-50298

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a phy

5.5
CVE-2026-50295

Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locall

6.2
CVE-2026-50294

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized atta

6.2
CVE-2026-49807

Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclos

6.6
CVE-2026-49804

Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a phys

5.5
CVE-2026-49801

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

6.5
CVE-2026-49799

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized att

4.6
CVE-2026-49794

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat

5.5
CVE-2026-49180

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize

6.1
CVE-2026-49174

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering

6.8
CVE-2026-49168

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges wi

4.7
CVE-2026-49167

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

6.5
CVE-2026-47282

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos

5.5
CVE-2026-45496

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthori

5.3
CVE-2026-44806

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to

5.5
CVE-2026-41087

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-40422

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started