Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature ov
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a netw
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to d
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securit
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started