ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which
In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a
In applyCustomDescription of SaveUi.java, there is a possible way to view other user's images due to a confused deputy.
The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an inf
Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the
An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software v
Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenti
Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escala
Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an aut
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an aut
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow a
Unchecked return value in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthent
Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentia
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V23
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V23
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V23
A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.251), Parasolid V35.1 (All versions < V35.1
The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment pr
Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-
A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to
Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenti
A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the f
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persi
Sametime is impacted by sensitive information passed in URL.
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficie
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administra
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient val
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in chan
Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based o
Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message tha
The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu
A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulne
A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by
A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vuln
A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an u
A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerab
A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of t
A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will cr
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to g
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information
Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue
Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `I
A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. T
A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some un
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started