Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL o
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When th
HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session h
HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sen
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session
HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit
HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed infor
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force o
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the appli
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clien
HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or ma
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metachara
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than
In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicio
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST
A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of th
A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an un
A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function Asse
A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file
A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decod
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attac
RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-
A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S
The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es
HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13
Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attack
CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_call
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite"
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started