User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perfo
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informati
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feat
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an a
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information ov
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tamper
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locall
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, s
Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Mana
Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer derefere
Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decr
Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes f
Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted reque
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started