Dell Secure Connect Gateway, 5.18, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemer
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to g
Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block oth
A vulnerability was found in South River WebDrive 18.00.5057. It has been declared as problematic. This vulnerability af
A vulnerability was found in Hyper CdCatalog 2.3.1. It has been classified as problematic. This affects an unknown part
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier a
Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.2
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid p
SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to ru
A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue
In the Linux kernel, the following vulnerability has been resolved: ceph: fix inode leak on getattr error in __fh_to_de
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix unconditional security_locked_down()
A vulnerability has been found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this v
A vulnerability classified as problematic was found in SourceCodester Online Job Portal 1.0. This vulnerability affects
In the Linux kernel, the following vulnerability has been resolved: i2c: validate user data in compat ioctl Wrong user
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, star
Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that expo
This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. Affect
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up t
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as problematic.
A vulnerability classified as problematic has been found in PHPGurukul Tourism Management System 1.0. Affected is an unk
Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure
A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown funct
A vulnerability, which was classified as problematic, has been found in Bdtask Bhojon Best Restaurant Management Softwar
The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser u
An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8
A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the w
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. A user's private brow
Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow v
A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerabi
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard
During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_
Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availabili
An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions p
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure S
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-or
Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configure
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started