Security Risk Severity

Medium Security Risks — Page 10

Published vulnerability pages grouped by medium severity. Use this page to review risks that need similar prioritization.

969 published medium risks

Medium severity

Showing 325–360 of 969 published risks.

Clear
mediumEPSS 0.003

CVE-2026-50298 windows 10 1607 vulnerability

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-50298windowsinput-validation

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-50299 windows 10 1607 vulnerability

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-50299windowsinput-validationmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-50300 windows 10 1607 vulnerability

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50300linuxwindowsinput-validationinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-50303 windows 10 1809 vulnerability

Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.

CVE-2026-50303windows

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-50316 windows 10 21h2 vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50316linuxwindowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-50350 windows 10 21h2 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

CVE-2026-50350windowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-50381 windows 10 21h2 vulnerability

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

CVE-2026-50381windowsmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-54988 365 apps vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-54988microsoftinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-49177 windows 10 1607 vulnerability

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

CVE-2026-49177windowsinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-50302 windows 10 21h2 vulnerability

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-50302windowscryptography

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-50310 windows 10 1809 vulnerability

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.

CVE-2026-50310windowsinput-validation

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-50312 windows 10 1607 vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-50312windowsmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.008

CVE-2026-50324 windows 10 1607 vulnerability

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-50324windowsdenial-of-service

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55023 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55023microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55026 365 apps vulnerability

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55026microsoftinput-validation

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55027 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55027microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55028 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55028microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55035 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55035microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55042 365 apps vulnerability

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55042microsoft

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55046 365 apps vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55046microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55047 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55047microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55050 365 apps vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-55050microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.006

CVE-2026-55051 sharepoint server vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVE-2026-55051microsoftssrf

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55057 365 apps vulnerability

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55057microsoftinput-validation

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55124 365 apps vulnerability

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-55124microsoftinput-validation

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55139 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55139microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55142 365 apps vulnerability

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-55142microsoft

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-56192 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56192microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-56195 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56195microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.009

CVE-2026-58539 windows 10 1607 vulnerability

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58539windowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-58543 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.

CVE-2026-58543windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-58545 windows 10 1607 vulnerability

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-58545linuxwindowsauthorization-bypass

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-58546 windows 10 1607 vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58546windows

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-58547 windows 10 1809 vulnerability

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-58547windowsmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-58638 windows 10 1809 vulnerability

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

CVE-2026-58638windowscryptography

Updated Jul 17, 2026

medium

CVE-2026-24227 tensorrt vulnerability

NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.

CVE-2026-24227unsafe-deserialization

Updated Jul 17, 2026