User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Ch
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyG
OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses
linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-
requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security featu
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physi
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose i
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a sec
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis
Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result
Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a netw
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny s
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature l
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofi
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memori
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo
The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functio
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiN
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vul
Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no add
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "move
Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security
Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User App
Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Appl
Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications m
Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.
Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Appl
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started