In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy
In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This cou
In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local
A vulnerability, which was classified as problematic, was found in flusity CMS. Affected is the function loadPostAddForm
A vulnerability, which was classified as problematic, has been found in flusity CMS. This issue affects the function loa
A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCr
A vulnerability, which was classified as problematic, was found in SourceCodester Sticky Notes App 1.0. This affects an
A vulnerability classified as problematic has been found in Dragon Path 707GR1 up to 20231022. Affected is an unknown fu
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime en
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user
sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of
A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issu
A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects
A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unkno
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this i
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by thi
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is a
Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for
Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for
Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusti
This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of c
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affe
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions
Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected
Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, product of Oracle Java S
On affected Wago products an remote attacker with administrative privileges can access files to which he has already acc
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could d
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a det
IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IB
Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained acc
Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it po
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can
An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate th
IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validati
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive informatio
A vulnerability was found in kphrx pleroma. It has been classified as problematic. This affects the function Pleroma.Emo
A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. Th
A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown pr
A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability af
A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unkno
A vulnerability was found in Portábilis i-Educar up to 2.7.5. It has been declared as problematic. Affected by this vuln
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature wh
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS
An issue was discovered in Plixer Scrutinizer before 19.3.1. It exposes debug logs to unauthenticated users at the /debu
Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authoriza
vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the linked resources
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started