Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 529/1777
5.5
CVE-2025-59203

Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclos

5.0
CVE-2025-59198

Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

5.5
CVE-2025-59197

Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose inform

5.5
CVE-2025-59190

Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

5.5
CVE-2025-59188

Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to

5.5
CVE-2025-59186

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i

6.5
CVE-2025-59185

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n

5.5
CVE-2025-59184

Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized at

6.5
CVE-2025-58739

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p

6.5
CVE-2025-58729

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d

4.7
CVE-2025-58719

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locall

6.5
CVE-2025-58717

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.5
CVE-2025-55700

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

5.5
CVE-2025-55699

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i

5.5
CVE-2025-55695

Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.

5.5
CVE-2025-55683

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i

6.1
CVE-2025-55682

Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe

5.1
CVE-2025-55679

Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2025-55676

Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker t

6.1
CVE-2025-55338

Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with

6.1
CVE-2025-55337

Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe

5.5
CVE-2025-55336

Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorize

6.2
CVE-2025-55334

Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security featur

6.1
CVE-2025-55333

Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security fea

6.1
CVE-2025-55332

Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe

6.1
CVE-2025-55330

Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe

5.5
CVE-2025-55325

Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

6.8
CVE-2025-55320

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager

4.8
CVE-2025-55248

Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose informat

6.5
CVE-2025-54603

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creat

6.3
CVE-2025-48813

Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

5.5
CVE-2025-47979

Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose i

6.5
CVE-2025-37148

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote atta

4.9
CVE-2025-37145

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit

4.9
CVE-2025-37144

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit

4.9
CVE-2025-37143

An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/

4.9
CVE-2025-37142

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope

4.9
CVE-2025-37141

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope

4.9
CVE-2025-37140

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope

6.0
CVE-2025-37139

A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot i

6.2
CVE-2025-37138

An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Cont

6.5
CVE-2025-37137

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili

6.5
CVE-2025-37136

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili

6.5
CVE-2025-37135

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili

6.8
CVE-2025-8429

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In

6.5
CVE-2025-59921

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0

6.4
CVE-2025-58324

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2,

6.7
CVE-2025-57716

An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.

5.3
CVE-2025-54973

A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in

6.8
CVE-2025-54893

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started