A vulnerability was found in slawkens MyAAC up to 0.8.13. It has been declared as problematic. This vulnerability affect
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as problema
A vulnerability was found in SourceCodester School Visitor Log e-Book 1.0. It has been rated as problematic. Affected by
A vulnerability, which was classified as problematic, has been found in code-projects Faculty Management System 1.0. Aff
A vulnerability classified as problematic was found in code-projects Faculty Management System 1.0. Affected by this vul
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulne
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the ser
A vulnerability has been found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositori
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be re
A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client coul
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects C
A vulnerability has been found in SourceCodester Online Student Management System 1.0 and classified as problematic. Aff
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different sup
Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacke
Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web in
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS se
A vulnerability, which was classified as problematic, was found in DFIRKuiper Kuiper 2.3.4. This affects the function un
A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vulnerability. A low-p
A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been classified as problematic. T
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only
Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker c
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 an
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The QUIC stack (quicly), as used by H2O up to commit
Umbraco is an ASP.NET content management system (CMS). Starting in version 7.0.0 and prior to versions 7.15.11, 8.18.9,
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1,
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0,
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices do
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack f
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path informa
This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2. Secure text fields ma
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document typ
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logic
A vulnerability classified as problematic has been found in linkding 1.23.0. Affected is an unknown function. The manipu
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. This iss
A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected by this issue is some un
A vulnerability classified as problematic was found in Typecho 1.2.1. Affected by this vulnerability is an unknown funct
A vulnerability classified as problematic has been found in Typecho 1.2.1. Affected is an unknown function of the file /
A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the fi
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started