Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature lo
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attac
TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-servi
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass.
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to in
Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allo
Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may all
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information d
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started