An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow
Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure o
A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function
A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unkno
The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access deb
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut
Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authoriz
Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a ne
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker
Processor optimization removal or modification of security-critical code in Windows Secure Kernel Mode allows an authori
Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass
Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker
Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead
After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to d
Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerabilit
Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker
Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevat
Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to
Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to
A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potenti
A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, pot
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows
SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote a
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Se
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 2
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Iva
The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific in
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 throug
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installat
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 throug
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started