Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifi
A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0.
A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulner
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and
A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0. Affected by
A vulnerability classified as problematic was found in qkmc-rk redbbs 1.0. Affected by this vulnerability is an unknown
A vulnerability classified as problematic has been found in CodeAstro Simple Banking System 1.0. This affects an unknown
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been rated as problematic. Affected by th
A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been declared as problematic. Aff
A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not rec
A vulnerability classified as problematic has been found in qkmc-rk redbbs 1.0. Affected is an unknown function of the c
The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to gen
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17 and iPadOS 17.
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and
The issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.6 and iPadOS 16
A path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. An app may be a
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, iOS
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.2 and iPadOS 16
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ
A vulnerability classified as problematic has been found in SourceCodester Engineers Online Portal 1.0. This affects an
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by t
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as problematic. Affected b
A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affect
A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability
A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown process
A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions <
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious pag
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This
A vulnerability, which was classified as problematic, has been found in Chanzhaoyu chatgpt-web 2.11.1. This issue affect
A vulnerability was found in Kashipara Food Management System up to 1.0. It has been rated as problematic. This issue af
A vulnerability was found in Kashipara Food Management System up to 1.0. It has been declared as problematic. This vulne
A vulnerability was found in Kashipara Food Management System up to 1.0. It has been classified as problematic. This aff
A vulnerability was found in Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown
A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authentic
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allo
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allo
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific direc
A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to
Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensiti
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, a
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started