Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authori
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information loca
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow
Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose informatio
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an
Protection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of pri
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where an attacker could cause a stack over
NVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure. A succ
Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow
Unquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow a
Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Ap
Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 20
Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User App
Incorrect default permissions for some Intel(R) Thread Director Visualizer software before version 1.1.1 within Ring 3:
Out-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may all
Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 wit
Uncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Application
Uncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applicat
Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.
Incorrect default permissions for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may all
Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Application
Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ri
Time-of-check time-of-use race condition for some ACAT before version 3.13 within Ring 3: User Applications may allow a
Improper neutralization for some Intel(R) Neural Compressor software before version v3.4 within Ring 3: User Application
Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 wit
Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applicati
Uncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may all
Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: Use
Null pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications m
Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications ma
Protection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of servic
Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within R
Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software a
Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl
Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appli
Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicat
Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications m
Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appli
Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow
Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicatio
Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring
Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.146
Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ri
Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation
External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: U
Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Devi
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started