A vulnerability was found in SimplePHPscripts FAQ Script PHP 2.3. It has been declared as problematic. Affected by this
Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denia
A vulnerability was found in Active It Zone Active eCommerce CMS 6.5.0. It has been declared as problematic. This vulner
A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the f
The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the nvdisasm binary file, where an attacker may
CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task
A vulnerability was found in RocketSoft Rocket LMS 1.7. It has been declared as problematic. This vulnerability affects
A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects
A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is
A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulne
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected b
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected
A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to re
Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could all
SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical applica
Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment
This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 9.5. An attac
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, m
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventur
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Big Sur 11.7.7, ma
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, iOS 16.5 and iPadOS 1
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.6.3, macOS Ven
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
Dell BIOS contains an Out-of-bounds Write vulnerability. An unauthenticated physical attacker may potentially exploit t
A vulnerability, which was classified as problematic, has been found in SourceCodester Game Result Matrix System 1.0. Af
A vulnerability classified as problematic was found in SourceCodester Online School Fees System 1.0. Affected by this vu
Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged rem
Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A r
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an
Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticate
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to s
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use tran
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24
A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manip
Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an admin
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected c
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive infor
A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolut
A vulnerability was found in SourceCodester Resort Management System 1.0. It has been declared as problematic. Affected
The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. T
A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vu
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use loc
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started