Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

2,090
Total
Showing 2,090 of 2,090 total · Page 1/42
3.3
CVE-2026-82596

A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDe

3.7
CVE-2026-82555

A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAu

2.6
CVE-2026-82656

Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated user

3.5
CVE-2026-82488

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component Us

3.5
CVE-2026-82483

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown functi

3.5
CVE-2026-82482

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an

3.7
CVE-2026-82562

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value un

2.7
CVE-2026-81200

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order informa

2.7
CVE-2026-77704

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the req

3.7
CVE-2026-55785

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptograph

3.7
CVE-2026-77063

multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter

3.7
CVE-2026-13735

Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_da

3.5
CVE-2026-82112

A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src

3.3
CVE-2026-38093

file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22

3.1
CVE-2026-82249

gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attacker

3.1
CVE-2026-82238

filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to w

3.1
CVE-2026-82237

filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cl

3.1
CVE-2026-82236

File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes ano

3.1
CVE-2026-52681

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the acco

3.1
CVE-2026-42393

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the confi

3.1
CVE-2026-40204

None None None No publicly available exploits are known.

3.7
CVE-2026-40203

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes

2.7
CVE-2026-79615

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question ba

3.5
CVE-2026-81848

A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fe

3.7
CVE-2026-81836

A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file sr

3.1
CVE-2026-59306

Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud

3.1
CVE-2026-59305

Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stre

3.1
CVE-2026-59304

Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Clou

3.1
CVE-2026-59303

Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cl

3.1
CVE-2026-59302

Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0

3.1
CVE-2026-59301

Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Fu

3.1
CVE-2026-59300

Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Func

3.1
CVE-2026-59299

Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Sp

3.1
CVE-2026-59298

Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cl

3.1
CVE-2026-59297

Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Functi

3.2
CVE-2026-59292

PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdi

2.0
CVE-2026-59291

Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Sprin

3.7
CVE-2026-59277

Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an

3.7
CVE-2026-54713

CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() gener

3.7
CVE-2026-81725

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attac

3.7
CVE-2026-81723

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that

3.5
CVE-2026-81717

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, wh

3.3
CVE-2026-81715

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the p

3.3
CVE-2026-81696

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info

3.3
CVE-2026-81695

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt

3.3
CVE-2026-81694

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the

3.3
CVE-2026-81685

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to

3.1
CVE-2026-81102

The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_serve

3.1
CVE-2025-62343

HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sess

3.5
CVE-2026-13416

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 2,090 CVE records rated LOW in our database.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started