Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to p
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information lo
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an
Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a phys
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a netw
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacke
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose informa
Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vuln
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to applicat
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cros
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cros
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to by
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. I
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an una
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose i
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a sec
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa
A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, F
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started