A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1
A vulnerability was found in Translator PoqDev Add-On 1.0.11 on Firefox. It has been rated as problematic. This issue af
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0,
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allow
A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unkno
A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some
A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filt
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to de
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or arch
Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a se
A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been rated as problematic. Affected by this issue
A vulnerability was found in Online Banquet Booking System 1.0 and classified as problematic. Affected by this issue is
A vulnerability has been found in Online Banquet Booking System 1.0 and classified as problematic. Affected by this vuln
A vulnerability, which was classified as problematic, was found in Online Banquet Booking System 1.0. Affected is an unk
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Courier Management System 1.
A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in BEECMS 4.0. This affe
A vulnerability, which was classified as problematic, has been found in SourceCodester Expense Tracker App v1. Affected
A vulnerability classified as problematic was found in SourceCodester Best Courier Management System 1.0. This vulnerabi
A vulnerability classified as problematic was found in ForU CMS. This vulnerability affects unknown code of the file /ad
A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this is
Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manag
Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting fr
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-bet
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up t
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in vers
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back
he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned i
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forg
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In Cilium clusters where Cili
Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause mali
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17, iOS
The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app m
The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app m
A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Son
The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Mont
The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, macO
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app
A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in tvOS 17, iOS
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started