Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 122/162
3.3
CVE-2023-40135

In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy

3.3
CVE-2023-40134

In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This cou

3.3
CVE-2023-40127

In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local

2.4
CVE-2023-5811

A vulnerability, which was classified as problematic, was found in flusity CMS. Affected is the function loadPostAddForm

2.4
CVE-2023-5810

A vulnerability, which was classified as problematic, has been found in flusity CMS. This issue affects the function loa

3.5
CVE-2023-5793

A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCr

3.5
CVE-2023-5791

A vulnerability, which was classified as problematic, was found in SourceCodester Sticky Notes App 1.0. This affects an

2.4
CVE-2023-5789

A vulnerability classified as problematic has been found in Dragon Path 707GR1 up to 20231022. Affected is an unknown fu

3.3
CVE-2023-42857

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma

3.3
CVE-2023-40405

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma

3.9
CVE-2023-46126

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime en

2.6
CVE-2023-34085

When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user

3.9
CVE-2023-46122

sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of

3.5
CVE-2023-5699

A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issu

3.5
CVE-2023-5698

A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects

3.5
CVE-2023-5697

A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unkno

3.5
CVE-2023-5696

A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this i

3.5
CVE-2023-5695

A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by thi

3.5
CVE-2023-5694

A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is a

3.7
CVE-2023-45822

Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for

2.7
CVE-2023-45809

Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for

3.6
CVE-2023-45145

Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusti

3.7
CVE-2023-38546

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of c

3.1
CVE-2023-22128

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affe

2.7
CVE-2023-22113

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions

2.4
CVE-2023-22075

Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected

2.4
CVE-2023-22074

Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected

3.7
CVE-2023-22025

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, product of Oracle Java S

2.7
CVE-2023-4089

On affected Wago products an remote attacker with administrative privileges can access files to which he has already acc

3.7
CVE-2022-43892

IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could d

2.7
CVE-2022-43891

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a det

2.7
CVE-2022-43893

IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IB

3.6
CVE-2023-45659

Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained acc

2.0
CVE-2023-45152

Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it po

3.7
CVE-2023-43814

Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can

3.5
CVE-2023-5421

An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate th

3.3
CVE-2023-35018

IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validati

2.3
CVE-2023-35013

IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive informatio

2.6
CVE-2023-5588

A vulnerability was found in kphrx pleroma. It has been classified as problematic. This affects the function Pleroma.Emo

2.4
CVE-2023-5585

A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. Th

3.5
CVE-2023-5582

A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown pr

3.5
CVE-2023-5581

A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability af

3.5
CVE-2023-5579

A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unkno

3.5
CVE-2023-5578

A vulnerability was found in Portábilis i-Educar up to 2.7.5. It has been declared as problematic. Affected by this vuln

3.8
CVE-2023-32973

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver

3.3
CVE-2023-5449

A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature wh

3.5
CVE-2023-41836

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS

3.7
CVE-2023-41263

An issue was discovered in Plixer Scrutinizer before 19.3.1. It exposes debug logs to unauthenticated users at the /debu

3.9
CVE-2023-45143

Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authoriza

3.7
CVE-2023-41881

vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the linked resources

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started