Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 178/1777
4.3
CVE-2026-45650

User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perfo

5.5
CVE-2026-45647

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el

5.5
CVE-2026-45634

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

6.8
CVE-2026-45608

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-45606

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

5.5
CVE-2026-45604

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informati

5.4
CVE-2026-45595

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feat

5.5
CVE-2026-45594

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an a

5.0
CVE-2026-45502

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information ov

6.5
CVE-2026-45501

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a

6.1
CVE-2026-45500

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows

6.2
CVE-2026-45491

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tamper

4.6
CVE-2026-45483

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server

4.6
CVE-2026-45479

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-45468

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-45467

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

5.4
CVE-2026-45465

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

5.4
CVE-2026-45464

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-45462

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.7
CVE-2026-45460

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.

6.5
CVE-2026-45454

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an

5.4
CVE-2026-45453

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.8
CVE-2026-45446

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD

5.5
CVE-2026-44821

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-44814

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

5.5
CVE-2026-44805

Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.

5.5
CVE-2026-42973

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t

5.5
CVE-2026-42972

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose

5.5
CVE-2026-42971

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t

5.5
CVE-2026-42970

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t

5.5
CVE-2026-42969

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locall

5.5
CVE-2026-42968

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

5.5
CVE-2026-42915

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

5.3
CVE-2026-42914

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

6.5
CVE-2026-42907

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in

5.5
CVE-2026-42906

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in

6.5
CVE-2026-42903

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

6.2
CVE-2026-42771

Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, s

5.3
CVE-2026-42769

Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Mana

5.9
CVE-2026-42767

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer derefere

5.9
CVE-2026-42766

Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decr

6.1
CVE-2026-42599

Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes f

6.1
CVE-2026-42573

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its

6.5
CVE-2026-3088

Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted reque

5.0
CVE-2026-35188

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ

5.4
CVE-2026-34692

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting

5.4
CVE-2026-33113

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.8
CVE-2026-28301

A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit

5.9
CVE-2026-0420

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co

4.5
CVE-2026-0418

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started