Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 11/162
3.8
CVE-2026-64614

Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL o

3.4
CVE-2026-12547

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When th

3.1
CVE-2026-56583

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session h

3.1
CVE-2026-56582

HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sen

2.6
CVE-2026-56581

HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session

2.2
CVE-2026-56580

HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit

3.1
CVE-2026-56579

HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed infor

2.2
CVE-2026-56578

HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities

3.1
CVE-2026-56577

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force o

3.1
CVE-2026-56586

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man

3.1
CVE-2026-56585

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the appli

3.1
CVE-2026-59849

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clien

3.7
CVE-2026-56587

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or ma

3.7
CVE-2026-56584

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software

3.9
CVE-2026-59846

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metachara

3.7
CVE-2026-59842

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than

2.6
CVE-2026-47275

In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicio

3.7
CVE-2026-26080

HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro

2.7
CVE-2026-10755

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST

2.6
CVE-2026-16218

A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of th

3.3
CVE-2026-16213

A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an un

2.6
CVE-2026-16211

A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function Asse

3.7
CVE-2026-16207

A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file

2.4
CVE-2026-16205

A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decod

3.5
CVE-2026-16203

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

3.5
CVE-2026-16202

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i

3.5
CVE-2026-16156

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par

3.5
CVE-2026-16155

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

3.7
CVE-2026-54335

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and

3.5
CVE-2026-54244

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp

3.1
CVE-2026-7364

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident

3.9
CVE-2026-14971

IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attac

3.3
CVE-2026-50185

RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-

3.5
CVE-2026-16073

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S

3.3
CVE-2025-59866

The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es

3.1
CVE-2026-21764

HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric

3.7
CVE-2026-21762

HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag

3.7
CVE-2024-23573

HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13

3.5
CVE-2024-32389

Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attack

3.7
CVE-2026-62994

CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD

3.1
CVE-2026-47088

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi

3.5
CVE-2026-47087

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A

3.5
CVE-2026-47086

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe

3.1
CVE-2026-47081

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac

3.1
CVE-2026-44970

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_call

2.5
CVE-2026-44969

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/

3.1
CVE-2026-35145

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to

3.0
CVE-2026-35143

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite"

2.6
CVE-2026-35142

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad

2.6
CVE-2026-35141

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started