Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 496/1777
6.5
CVE-2025-60722

Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authori

6.5
CVE-2025-60708

Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.

5.5
CVE-2025-60706

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.

5.5
CVE-2025-59513

Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information loca

5.5
CVE-2025-59510

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow

5.5
CVE-2025-59509

Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose informatio

5.5
CVE-2025-59240

Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to

6.7
CVE-2025-47179

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

6.7
CVE-2025-35972

Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an

6.4
CVE-2025-35968

Protection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of pri

6.5
CVE-2025-33202

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where an attacker could cause a stack over

5.3
CVE-2025-33185

NVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure.  A succ

6.6
CVE-2025-32732

Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow

6.7
CVE-2025-32449

Unquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow a

6.5
CVE-2025-32446

Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Ap

6.7
CVE-2025-32038

Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 20

6.7
CVE-2025-32001

Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User App

6.7
CVE-2025-31940

Incorrect default permissions for some Intel(R) Thread Director Visualizer software before version 1.1.1 within Ring 3:

5.6
CVE-2025-31937

Out-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may all

6.7
CVE-2025-31931

Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 wit

6.7
CVE-2025-31647

Uncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Application

6.7
CVE-2025-31645

Uncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applicat

6.1
CVE-2025-31146

Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.

6.7
CVE-2025-30518

Incorrect default permissions for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may all

6.7
CVE-2025-30506

Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Application

6.7
CVE-2025-30182

Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ri

4.4
CVE-2025-27725

Time-of-check time-of-use race condition for some ACAT before version 3.13 within Ring 3: User Applications may allow a

5.7
CVE-2025-27712

Improper neutralization for some Intel(R) Neural Compressor software before version v3.4 within Ring 3: User Application

6.7
CVE-2025-27711

Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 wit

6.5
CVE-2025-27710

Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applicati

5.5
CVE-2025-27249

Uncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may all

6.7
CVE-2025-27246

Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: Use

5.5
CVE-2025-26694

Null pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications m

5.9
CVE-2025-26405

Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications ma

6.5
CVE-2025-26402

Protection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of servic

6.7
CVE-2025-25059

Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within R

6.7
CVE-2025-24918

Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software a

6.5
CVE-2025-24863

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl

6.3
CVE-2025-24848

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appli

4.5
CVE-2025-24847

Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicat

6.7
CVE-2025-24842

Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications m

6.5
CVE-2025-24834

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appli

6.5
CVE-2025-24519

Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow

4.5
CVE-2025-24516

Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicatio

5.6
CVE-2025-24512

Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring

6.7
CVE-2025-24491

Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.146

6.7
CVE-2025-24327

Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ri

6.7
CVE-2025-22391

Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation

6.7
CVE-2025-20614

External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: U

6.7
CVE-2025-20065

Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Devi

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started