Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 614/1777
5.9
CVE-2025-49558

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a

6.7
CVE-2025-48807

Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to

5.3
CVE-2025-25007

Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to pe

5.3
CVE-2025-25006

Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform

6.5
CVE-2025-25005

Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network

4.1
CVE-2025-20044

Improper locking for some Intel(R) TDX Module firmware before version 1.5.13 may allow a privileged user to potentially

5.5
CVE-2025-49568

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclo

5.5
CVE-2025-49567

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead

6.7
CVE-2025-27717

Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enabl

6.7
CVE-2025-27559

Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated use

5.5
CVE-2025-27537

Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platfor

5.7
CVE-2025-26472

Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge

6.7
CVE-2025-26470

Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may

6.7
CVE-2025-26404

Uncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to pote

6.7
CVE-2025-24923

Uncontrolled search path in some Intel(R) AI for Enterprise Retrieval-augmented Generation software may allow an authent

6.6
CVE-2025-24921

Improper neutralization for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform

5.8
CVE-2025-24840

Improper access control for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform

6.5
CVE-2025-24835

Protection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 3

6.5
CVE-2025-24515

NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial

6.5
CVE-2025-24323

Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before

4.4
CVE-2025-24313

Improper access control for some Device Plugins for Kubernetes software maintained by Intel before version 0.32.0 may al

6.7
CVE-2025-24302

Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticate

6.0
CVE-2025-24296

Improper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user

6.7
CVE-2025-22838

Uncontrolled search path for some Intel(R) RealSense(TM) Dynamic Calibrator software before version 2.14.2.0 may allow a

4.4
CVE-2025-22392

Out-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to

6.7
CVE-2025-21093

Uncontrolled search path element for some Intel(R) Driver & Support Assistant Tool software before version 24.6.49.8

6.5
CVE-2025-21090

Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to p

6.7
CVE-2025-20627

Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.1 may allow an authe

6.7
CVE-2025-20099

Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user

6.7
CVE-2025-20092

Uncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to pot

5.5
CVE-2025-20090

Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authen

6.7
CVE-2025-20087

Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated

5.3
CVE-2025-20077

Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) referenc

6.0
CVE-2025-20067

Observable timing discrepancy in firmware for some Intel(R) CSME and Intel(R) SPS may allow a privileged user to potenti

6.7
CVE-2025-20048

Uncontrolled search path for the Intel(R) Trace Analyzer and Collector software all verions may allow an authenticated u

4.4
CVE-2025-20025

Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticate

6.7
CVE-2025-20023

Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to p

6.7
CVE-2025-20017

Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated u

5.6
CVE-2024-33607

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user

4.3
CVE-2025-8452

By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-fu

6.4
CVE-2025-55011

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskF

6.1
CVE-2025-54800

Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can intro

6.5
CVE-2025-8310

Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows

5.5
CVE-2025-5468

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure bef

4.9
CVE-2025-5466

XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before

6.3
CVE-2024-38805

EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A succe

4.2
CVE-2025-22834

AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Success

6.7
CVE-2025-22830

APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful ex

6.1
CVE-2025-43735

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024

5.5
CVE-2025-40766

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started