Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spo
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose informati
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose informatio
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose informati
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature l
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attac
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to di
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose informati
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perfo
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to d
Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execut
Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-leve
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio
In the Linux kernel, the following vulnerability has been resolved: ip6_gre: make ip6gre_header() robust Over the year
In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix reference count leak when using error rou
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Check for the presence of LS_NLA_TYPE_DG
In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: validate PHY address before use Th
In the Linux kernel, the following vulnerability has been resolved: mptcp: fallback earlier on simult connection Syzka
In the Linux kernel, the following vulnerability has been resolved: iavf: fix off-by-one issues in iavf_config_rss_reg(
In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fix leaking the multicast GID table refere
In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Avoid NULL pointer deref for evicted BOs
In the Linux kernel, the following vulnerability has been resolved: ASoC: stm32: sai: fix OF node leak on probe The re
In the Linux kernel, the following vulnerability has been resolved: net: nfc: fix deadlock between nfc_unregister_devic
In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allo
In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Limit num_syncs to prevent oversized all
In the Linux kernel, the following vulnerability has been resolved: ublk: fix deadlock when reading partition table Wh
fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attac
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Fir
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderb
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thun
The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Expos
Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, crea
By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO
The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability
Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a m
Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthen
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started