Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil
WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions c
Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by `SORT_RO` and a
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.5. An
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternati
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to c
Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console acces
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automati
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Au
Vyper is a Pythonic Smart Contract Language. In affected versions the order of evaluation of the arguments of the builti
Vyper is a Pythonic Smart Contract Language. For the following (probably non-exhaustive) list of expressions, the compil
The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown func
A vulnerability classified as problematic has been found in TOTVS RM 12.1. Affected is an unknown function of the file L
In a typical Virtual Machine Monitor (VMM) there are several components, such as boot loader, virtual device drivers, vi
A vulnerability was found in Infosoftbd Clcknshop 1.0.0. It has been declared as problematic. This vulnerability affects
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting fro
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting fr
Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Gr
Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support
IBM Security Verify Information Queue 10.0.4 and 10.0.5 stores sensitive information in plain clear text which can be re
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.
Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged
xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session es
Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the ev
Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability whic
A vulnerability was found in glb Meetup Tag Extension 0.1 on MediaWiki. It has been rated as problematic. This issue aff
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in nikooo777 ckSurf up to 1.19.2. It has been declared as prob
A vulnerability was found in Doc2k RE-Chat 1.0. It has been classified as problematic. This affects an unknown part of t
A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. Affected
A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has been rated as problematic. Affected by this issue is
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic.
A vulnerability, which was classified as problematic, was found in NeoMind Fusion Platform up to 20230731. Affected is a
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
Silverware Games is a premium social network where people can play games online. When using the Recovery form, a noticea
An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit
A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If e
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the s
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script conten
Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privilege
A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some
A vulnerability has been found in MaximaTech Portal Executivo 21.9.1.140 and classified as problematic. This vulnerabili
A vulnerability, which was classified as problematic, has been found in tdevs Hyip Rio 2.1. Affected by this issue is so
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started