A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b
A vulnerability classified as problematic has been found in SourceCodester Service Provider Management System 1.0. Affec
A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file
A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been classified as problematic.
In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username coll
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. Thi
A vulnerability classified as problematic has been found in Kau-Boy Backend Localization Plugin 2.0 on WordPress. Affect
A vulnerability was found in Kau-Boy Backend Localization Plugin up to 1.6.1 on WordPress. It has been rated as problema
Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update th
NVIDIA CUDA Toolkit for Linux and Windows contains a vulnerability in cuobjdump, where a division-by-zero error may enab
NVIDIA CUDA Toolkit SDK for Linux and Windows contains a NULL pointer dereference in cuobjdump, where a local user runni
Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform co
Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows att
A vulnerability was found in Dream Technology mica up to 3.0.5. It has been classified as problematic. Affected is an un
A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as problematic. This issue affects s
A vulnerability classified as problematic was found in Campcodes Coffee Shop POS System 1.0. Affected by this vulnerabil
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a s
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a spe
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a speci
Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a speciall
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by th
Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modu
Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a
Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggl
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affecte
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)
Vulnerability in the Oracle Solaris product of Oracle Systems (component: IPS repository daemon). The supported versio
A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This v
A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as problematic. Affected by t
Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later t
A vulnerability, which was classified as problematic, was found in InternalError503 Forget It up to 1.3. This affects an
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods
Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager
A vulnerability classified as problematic was found in Google Analytics Top Content Widget Plugin up to 1.5.6 on WordPre
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users
A vulnerability classified as problematic was found in SourceCodester Vehicle Service Management System 1.0. This vulner
A vulnerability classified as problematic has been found in SourceCodester Vehicle Service Management System 1.0. This a
A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been rated as problematic. Aff
In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger
A vulnerability, which was classified as problematic, has been found in Campcodes Online Traffic Offense Management Syst
A vulnerability classified as problematic was found in Campcodes Online Traffic Offense Management System 1.0. This vuln
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started