Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 709/1777
5.6
CVE-2025-24495

Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an

5.5
CVE-2025-22895

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge

6.5
CVE-2025-22892

Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4

4.3
CVE-2025-22844

Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticat

6.1
CVE-2025-22448

Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an a

4.6
CVE-2025-22446

Inadequate encryption strength for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authen

4.1
CVE-2025-21100

Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged use

6.7
CVE-2025-21099

Uncontrolled search path for some Intel(R) Graphics software may allow an authenticated user to potentially enable escal

4.5
CVE-2025-21081

Protection mechanism failure for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenti

6.7
CVE-2025-20629

Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before v

5.7
CVE-2025-20624

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge

5.6
CVE-2025-20623

Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio

5.5
CVE-2025-20616

Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an aut

5.5
CVE-2025-20612

Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow

4.7
CVE-2025-20611

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge

6.7
CVE-2025-20108

Uncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4

6.5
CVE-2025-20103

Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user

6.7
CVE-2025-20095

Incorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated

6.7
CVE-2025-20079

Uncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escala

5.0
CVE-2025-20076

Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticat

6.5
CVE-2025-20071

NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial

6.1
CVE-2025-20062

Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti

6.5
CVE-2025-20054

Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to pote

5.7
CVE-2025-20047

Improper locking in the Intel(R) Integrated Connectivity I/O interface (CNVi) for some Intel(R) Core™ Ultra Processors m

6.7
CVE-2025-20043

Uncontrolled search path for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user

6.7
CVE-2025-20041

Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics

6.6
CVE-2025-20039

Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti

5.3
CVE-2025-20034

Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M5

6.5
CVE-2025-20031

Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denia

6.1
CVE-2025-20026

Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauth

5.7
CVE-2025-20022

Insufficient control flow management for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow a p

6.7
CVE-2025-20015

Uncontrolled search path element for some Intel(R) Ethernet Connection software before version 29.4 may allow an authent

5.5
CVE-2025-20013

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge

4.9
CVE-2025-20012

Incorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enabl

4.1
CVE-2025-20009

Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards m

6.1
CVE-2024-48869

Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when

6.7
CVE-2024-47800

Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enabl

6.7
CVE-2024-47795

Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authe

6.7
CVE-2024-47550

Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to pote

6.7
CVE-2024-46895

Uncontrolled search path for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101

6.7
CVE-2024-45371

Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6077 may allow

5.6
CVE-2024-45332

Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio

5.6
CVE-2024-43420

Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio

5.3
CVE-2024-43101

Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.10

6.7
CVE-2024-39833

Uncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentia

5.9
CVE-2024-39758

Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 31.0.101.4032 may allow

6.7
CVE-2024-31073

Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially ena

6.1
CVE-2024-29222

Out-of-bounds write for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable den

5.6
CVE-2024-28956

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) P

6.7
CVE-2024-28954

Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentiall

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started