Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge
Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4
Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticat
Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an a
Inadequate encryption strength for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authen
Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged use
Uncontrolled search path for some Intel(R) Graphics software may allow an authenticated user to potentially enable escal
Protection mechanism failure for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenti
Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before v
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio
Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an aut
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge
Uncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user
Incorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated
Uncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escala
Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticat
NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial
Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to pote
Improper locking in the Intel(R) Integrated Connectivity I/O interface (CNVi) for some Intel(R) Core™ Ultra Processors m
Uncontrolled search path for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user
Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics
Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti
Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M5
Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denia
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauth
Insufficient control flow management for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow a p
Uncontrolled search path element for some Intel(R) Ethernet Connection software before version 29.4 may allow an authent
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge
Incorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enabl
Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards m
Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when
Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enabl
Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authe
Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to pote
Uncontrolled search path for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101
Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6077 may allow
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio
Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.10
Uncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentia
Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 31.0.101.4032 may allow
Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially ena
Out-of-bounds write for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable den
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) P
Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentiall
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started