An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash
Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authentica
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el
Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the us
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Sta
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoi
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attac
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacen
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started