A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction cou
HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error me
HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application d
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to m
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute ar
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute ar
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This issue affect
A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnera
A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unkn
A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affe
A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerabili
A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by thi
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing fre
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources
A vulnerability classified as problematic has been found in HuiRan Host Reseller System up to 2.0.0. Affected is an unkn
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. This vulne
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. This aff
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. Affected b
Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3
A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all
A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected
A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 3
A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authe
A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the
Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12.
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by t
A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic. This affects an
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause i
Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information l
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause d
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause d
A vulnerability was found in code-projects Client Details System 1.0. It has been rated as problematic. Affected by this
Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker F
Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include
Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission
A vulnerability classified as problematic was found in code-projects Record Management System 1.0. Affected by this vuln
A vulnerability classified as problematic has been found in code-projects Record Management System 1.0. Affected is an u
A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problemati
A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this
A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerab
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in icret EasyImages 2.8.3. This vuln
A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue aff
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started