A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates tempora
A vulnerability classified as problematic was found in smallweigit Avue up to 3.4.4. Affected by this vulnerability is a
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administr
SQL-Injection in Harbor allows priviledge users to leak the task IDs
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17
This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and
Authentication Bypass by Spoofing vulnerability in Acurax Under Construction / Maintenance Mode from Acurax allows Authe
Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.
A vulnerability was found in Likeshop up to 2.5.7 and classified as problematic. This issue affects some unknown process
Kofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows r
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly whe
An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms
A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creati
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the curr
An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos
An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All I
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Vongries Ultimate Dashboard allows Acc
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hid
Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functional
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Webcraftic Hide login page allows Accessing
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in LWS LWS Hide Login allows Accessing Function
Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constraine
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affe
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking Syst
Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows a
Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly r
Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the
MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions ca
A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6.
Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL d
Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 F
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Aff
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function
Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU
Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 1
A vulnerability, which was classified as problematic, has been found in oretnom23 Online Car Wash Booking System 1.0. Th
A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown
A vulnerability classified as problematic has been found in jsy-1 short-url 1.0.0. Affected is an unknown function of th
A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown
A vulnerability was found in Kashipara College Management System 1.0 and classified as problematic. Affected by this iss
A vulnerability has been found in Kashipara College Management System 1.0 and classified as problematic. Affected by thi
A vulnerability, which was classified as problematic, was found in Kashipara College Management System 1.0. Affected is
A vulnerability, which was classified as problematic, has been found in Kashipara College Management System 1.0. This is
A vulnerability classified as problematic was found in Kashipara College Management System 1.0. This vulnerability affec
A vulnerability classified as problematic has been found in Kashipara College Management System 1.0. This affects an unk
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started