Improper conditions check for some Intel(R) Arc™ GPU may allow an authenticated user to potentially enable denial of ser
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authentica
Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to
Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch a
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locall
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou
Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacke
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to dis
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis
Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose info
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an a
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privil
A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled a
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to a
An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the sour
nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 all
An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a C
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the f
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the f
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formM
CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console.
A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 th
A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, po
Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not co
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not pro
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started