SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection
Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an Access of Uninitialized Point
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.
Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and us
Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values l
Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an over
Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for
Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signe
Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset fo
Vim is an open source command line text editor. When closing a window, vim may try to access already freed window struct
Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by an Access of Uninitialized Pointer
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls ne
Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial deni
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disc
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access
Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a deni
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a secu
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the log
Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user
Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may
Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 m
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potential
Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory cont
A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masque
Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to poten
Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated use
Improper Initialization for some Intel Unison software may allow a privileged user to potentially enable denial of servi
Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enabl
Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service vi
Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalatio
Improper initialization for some Intel Unison software may allow an authenticated user to potentially enable information
Exposure of sensitive system information due to uncleared debug information for some Intel Unison software may allow an
Incomplete cleanup for some Intel Unison software may allow an authenticated user to potentially enable information disc
Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of servi
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-b
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 an
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web
A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks
PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exist
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul
A vulnerability has been found in Intelbras RX 1500 1.1.9 and classified as problematic. Affected by this vulnerability
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Teli
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started