Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 646/1777
4.9
CVE-2025-4663

An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow

5.5
CVE-2025-47135

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure o

6.3
CVE-2025-7187

A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function

6.3
CVE-2025-7186

A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unkno

6.5
CVE-2025-53512

The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access deb

5.7
CVE-2025-49722

Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over

6.5
CVE-2025-49706 KEV

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ

5.5
CVE-2025-49684

Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.

6.5
CVE-2025-49681

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.5
CVE-2025-49671

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an

6.5
CVE-2025-49670

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

5.5
CVE-2025-49664

Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authoriz

5.5
CVE-2025-49658

Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.

5.9
CVE-2025-48823

Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a ne

6.8
CVE-2025-48818

Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur

5.5
CVE-2025-48812

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

6.7
CVE-2025-48811

Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker

5.5
CVE-2025-48810

Processor optimization removal or modification of security-critical code in Windows Secure Kernel Mode allows an authori

5.5
CVE-2025-48809

Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker

5.5
CVE-2025-48808

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i

6.8
CVE-2025-48804

Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass

6.7
CVE-2025-48803

Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker

6.5
CVE-2025-48802

Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.

6.8
CVE-2025-48800

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph

6.8
CVE-2025-48003

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph

5.7
CVE-2025-48002

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent

6.8
CVE-2025-48001

Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur

6.8
CVE-2025-47999

Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

6.2
CVE-2025-47980

Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker

6.5
CVE-2025-47978

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

5.5
CVE-2025-47109

After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead

5.5
CVE-2025-43587

After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to d

5.5
CVE-2025-43580

Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerabilit

5.5
CVE-2025-26636

Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker

6.0
CVE-2025-21195

Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevat

5.5
CVE-2025-21168

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.5
CVE-2025-21167

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to

5.6
CVE-2024-36357

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potenti

5.6
CVE-2024-36350

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, pot

6.5
CVE-2025-5464

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe

6.6
CVE-2025-0293

CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows

5.5
CVE-2025-0292

SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote a

4.3
CVE-2025-7182

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A

5.5
CVE-2025-5463

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Se

4.9
CVE-2025-5451

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 2

6.3
CVE-2025-5450

Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Iva

5.4
CVE-2025-53480

The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific in

6.4
CVE-2025-3630

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 throug

4.3
CVE-2025-2827

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installat

5.4
CVE-2025-2793

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 throug

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started