Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 48/1777
5.3
CVE-2026-65777

Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature ov

6.5
CVE-2026-65769

Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to

5.5
CVE-2026-65662

Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.

4.6
CVE-2026-64922

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

5.5
CVE-2026-64917

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

4.6
CVE-2026-64916

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-64902

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

5.5
CVE-2026-64899

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

4.6
CVE-2026-64897

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

5.5
CVE-2026-63531

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63530

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63529

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63528

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63524

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63521

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-63517

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

6.5
CVE-2026-63516

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over

6.5
CVE-2026-63512

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network

4.6
CVE-2026-62917

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ

6.5
CVE-2026-62915

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net

6.5
CVE-2026-62912

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw

6.5
CVE-2026-62902

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information

5.9
CVE-2026-62900

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose

5.9
CVE-2026-62899

Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker

5.5
CVE-2026-62887

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

6.7
CVE-2026-62883

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

4.3
CVE-2026-62882

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove

6.7
CVE-2026-62881

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

5.5
CVE-2026-62842

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

6.5
CVE-2026-62839

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov

6.5
CVE-2026-62837

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a netw

4.6
CVE-2026-62829

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

6.5
CVE-2026-62814

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

5.5
CVE-2026-62798

Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62796

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62793

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62786

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

6.5
CVE-2026-62782

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

5.5
CVE-2026-62775

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to d

6.7
CVE-2026-62769

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

5.3
CVE-2026-62757

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securit

6.5
CVE-2026-62750

Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad

5.5
CVE-2026-62746

Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.

6.5
CVE-2026-62745

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

5.5
CVE-2026-62743

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

6.5
CVE-2026-62742

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

5.5
CVE-2026-62740

Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally

5.5
CVE-2026-62738

Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62730

Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

6.5
CVE-2026-62720

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started