Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclos
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose inform
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locall
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe
Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally.
Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker t
Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorize
Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security featur
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security fea
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose informat
An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creat
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose i
A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote atta
Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit
Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit
An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot i
An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Cont
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2,
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.
A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started