Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could lead to disclosur
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security rest
An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiS
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, v
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For
A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all vers
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiC
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclo
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to
Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to discl
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl
Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disc
Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service ov
Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premi
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon
The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started