PyDrive2 is a wrapper library of google-api-python-client that simplifies many common Google Drive API V2 tasks. Unsafe
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct ini
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security v
Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensit
Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive informati
fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certa
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications
A vulnerability was found in librespeed speedtest up to 5.2.4. It has been declared as problematic. Affected by this vul
A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This i
A vulnerability, which was classified as problematic, was found in SourceCodester Online Quiz System 1.0. This affects a
A vulnerability, which was classified as problematic, has been found in PHPEMS 7.0. This issue affects some unknown proc
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as problematic. This issue affects some unknown pro
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. This vulnerability affects unkno
A vulnerability has been found in SourceCodester User Registration and Login System 1.0 and classified as problematic. A
A vulnerability, which was classified as problematic, was found in SourceCodester User Registration and Login System 1.0
Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is tran
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-cod
An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting fr
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic.
A vulnerability was found in SourceCodester Book Borrower System 1.0 and classified as problematic. This issue affects s
A vulnerability classified as problematic was found in ZenTao PMS 18.8. Affected by this vulnerability is an unknown fun
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rat
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv
Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers w
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-admini
The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat
The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials u
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowi
A vulnerability was found in SourceCodester URL Shortener 1.0. It has been declared as problematic. Affected by this vul
A vulnerability was found in CSZCMS 1.3.0. It has been classified as problematic. This affects an unknown part of the fi
A vulnerability has been found in SourceCodester Best Courier Management System 1.0 and classified as problematic. Affec
A vulnerability, which was classified as problematic, was found in SourceCodester Best Courier Management System 1.0. Af
google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request
A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by
Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to dele
IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a local user to perform unauthorized actions due to imprope
IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a privileged user to obtain sensitive information due to mi
Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` com
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS In
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application err
It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a m
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started