Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 120/162
3.1
CVE-2023-47643

SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection

3.3
CVE-2023-47072

Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an Access of Uninitialized Point

3.5
CVE-2023-48649

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name.

2.8
CVE-2023-48237

Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and us

2.8
CVE-2023-48236

Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values l

2.8
CVE-2023-48235

Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an over

2.8
CVE-2023-48234

Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for

2.8
CVE-2023-48233

Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signe

3.9
CVE-2023-48232

Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset fo

3.9
CVE-2023-48231

Vim is an open source command line text editor. When closing a window, vim may try to access already freed window struct

3.3
CVE-2023-47060

Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by an Access of Uninitialized Pointer

2.7
CVE-2023-30954

The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls ne

2.7
CVE-2023-23549

Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial deni

3.5
CVE-2023-43588

Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disc

3.7
CVE-2023-39206

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access

3.1
CVE-2023-39202

Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a deni

3.4
CVE-2023-47641

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a secu

3.7
CVE-2023-47126

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the log

3.9
CVE-2023-38411

Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user

3.3
CVE-2023-28723

Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may

3.8
CVE-2023-28404

Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 m

2.6
CVE-2023-22329

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potential

2.3
CVE-2023-22313

Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to

1.9
CVE-2023-20526

Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the

3.3
CVE-2023-20521

TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory cont

3.3
CVE-2023-20519

A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masque

2.2
CVE-2022-46647

Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to poten

2.2
CVE-2022-46646

Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated use

1.9
CVE-2022-46301

Improper Initialization for some Intel Unison software may allow a privileged user to potentially enable denial of servi

3.3
CVE-2022-46299

Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enabl

1.9
CVE-2022-46298

Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service vi

2.2
CVE-2022-45469

Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalatio

3.3
CVE-2022-45109

Improper initialization for some Intel Unison software may allow an authenticated user to potentially enable information

3.3
CVE-2022-43666

Exposure of sensitive system information due to uncleared debug information for some Intel Unison software may allow an

3.3
CVE-2022-43477

Incomplete cleanup for some Intel Unison software may allow an authenticated user to potentially enable information disc

1.9
CVE-2022-41659

Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of servi

1.9
CVE-2022-23830

SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest

2.5
CVE-2021-46766

Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP

1.9
CVE-2021-26345

Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-b

2.3
CVE-2023-45585

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 an

3.7
CVE-2023-44322

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM

2.7
CVE-2023-44321

Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web

3.5
CVE-2023-43503

A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks

2.9
CVE-2023-47625

PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exist

3.1
CVE-2023-42815

Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul

3.1
CVE-2023-42814

Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul

2.4
CVE-2023-6103

A vulnerability has been found in Intelbras RX 1500 1.1.9 and classified as problematic. Affected by this vulnerability

3.3
CVE-2023-47614

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Teli

3.4
CVE-2023-47121

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version

3.5
CVE-2023-6075

A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started