A lock screen issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. A user may be
The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPad
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app
A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200,
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scriptin
Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo att
plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity conten
OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the err
IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts,
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document craftin
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.8.8.
A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core/cec-api.c leaks one byte of kernel memo
A vulnerability, which was classified as problematic, has been found in China Unicom TEWA-800G 4.16L.04_CT2015_Yueme. Af
A vulnerability classified as problematic has been found in Tongda OA 11.10. Affected is an unknown function of the file
A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknow
A vulnerability was found in Planno 23.04.04. It has been classified as problematic. This affects an unknown part of the
A vulnerability, which was classified as problematic, was found in SourceCodester AC Repair and Services System 1.0. Aff
A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the f
A vulnerability has been found in Pluck CMS 4.7.18 and classified as problematic. This vulnerability affects unknown cod
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable
Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 co
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a ver
A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901. Affected by this vulnerabili
A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerabi
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown fun
A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Conf
The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with n
An issue was discovered in the NPU kernel driver in Samsung Exynos Mobile Processor 9820, 980, 2100, 2200, 1280, and 138
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected app
Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issu
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an a
The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Big Sur
Search queries in the default search engine could appear to have been the currently navigated URL if the search query it
A vulnerability classified as problematic has been found in SourceCodester Contact Manager App 1.0. This affects an unkn
A vulnerability, which was classified as problematic, was found in SourceCodester Take-Note App 1.0. This affects an unk
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
A vulnerability classified as problematic has been found in SourceCodester Simple Book Catalog App 1.0. Affected is an u
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with g
An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the e
An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor (Exynos 980, Exynos 850, Exynos 2100,
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an out-of-bounds read vulnerabi
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an out-of-bounds read vulnerabi
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an out-of-bounds read vulnerabi
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an out-of-bounds read vulnerabi
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an out-of-bounds read vulnerabi
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an out-of-bounds read vulnerabi
Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Use-After-Free vulnerability
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started