In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication,
A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authe
A vulnerability, which was classified as problematic, has been found in y_project RuoYi up to 4.7.7. Affected by this is
A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2
A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function
A vulnerability classified as problematic has been found in Bug Finder ChainCity Real Estate Investment Platform 1.0. Af
A vulnerability has been found in Boom CMS 8.0.7 and classified as problematic. Affected by this vulnerability is the fu
A vulnerability, which was classified as problematic, was found in PaulPrinting CMS 2018. Affected is an unknown functio
A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This iss
A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects u
A vulnerability was found in PaulPrinting CMS 2018. It has been rated as problematic. Affected by this issue is some unk
A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vu
A vulnerability was found in Webile 1.0.1. It has been classified as problematic. Affected is an unknown function of the
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpecte
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability co
A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknow
A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown f
A vulnerability classified as problematic has been found in GZ Scripts Car Rental Script 1.8. Affected is an unknown fun
A vulnerability was found in Creativeitem Atlas Business Directory Listing 2.13 and classified as problematic. Affected
A vulnerability has been found in Creativeitem Atlas Business Directory Listing 2.13 and classified as problematic. Affe
A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affecte
A vulnerability classified as problematic has been found in Creativeitem Mastery LMS 1.2. This affects an unknown part o
A vulnerability was found in Creativeitem Academy LMS 5.15. It has been rated as problematic. Affected by this issue is
IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without th
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 a
Vulnerability in the Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Gra
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE
Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affect
Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fid
Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fid
A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic.
Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowi
Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.
Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any us
Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the
Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic.
IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation
A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown par
A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. It has been classified as problematic. This affe
A vulnerability was found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this issue is some un
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started