Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to version 1.13.4, when
The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is unini
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improp
Microsoft Power Apps Spoofing Vulnerability
A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #
A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown func
A vulnerability has been found in OTCMS up to 6.62 and classified as problematic. Affected by this vulnerability is an u
A vulnerability, which was classified as problematic, was found in OTCMS up to 6.62. Affected is an unknown function of
A vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown co
A vulnerability, which was classified as problematic, was found in SourceCodester Online School Fees System 1.0. This af
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A m
Windows Snipping Tool Information Disclosure Vulnerability
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the con
A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All vers
An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versi
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware
SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an
A vulnerability classified as problematic was found in cchetanonline WP-CopyProtect up to 3.0.0. This vulnerability affe
UmbracoIdentityExtensions is an Umbraco add-on package that enables easy extensibility points for ASP.Net Identity integ
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affec
A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affec
MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app settings. Archives do not inc
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.1
The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based
A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. A
A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the functio
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit se
The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.
An attacker with local access to the machine could record the traffic, which could allow them to resend requests witho
An issue has been discovered in GitLab CE/EE affecting all versions starting from 1.2 before 15.10.8, all versions start
An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions startin
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions star
A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this
A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is
A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased availability.
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use caus
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL c
A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic. This vuln
A vulnerability classified as problematic was found in Arborator Server. This vulnerability affects the function start o
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Fuzzy SWMP. It has been rated as problematic. This issue af
A vulnerability, which was classified as problematic, was found in Gravity Forms DPS PxPay Plugin up to 1.4.2 on WordPre
A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started