Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 135/162
3.5
CVE-2023-2350

A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b

3.5
CVE-2023-2349

A vulnerability classified as problematic has been found in SourceCodester Service Provider Management System 1.0. Affec

3.5
CVE-2023-2294

A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file

2.4
CVE-2023-2293

A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been classified as problematic.

3.3
CVE-2023-25815

In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git

3.8
CVE-2022-23721

PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username coll

3.1
CVE-2023-28847

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.

3.1
CVE-2023-2281

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. Thi

3.5
CVE-2012-10014

A vulnerability classified as problematic has been found in Kau-Boy Backend Localization Plugin 2.0 on WordPress. Affect

3.5
CVE-2012-10013

A vulnerability was found in Kau-Boy Backend Localization Plugin up to 1.6.1 on WordPress. It has been rated as problema

3.9
CVE-2023-30544

Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update th

3.3
CVE-2023-25511

NVIDIA CUDA Toolkit for Linux and Windows contains a vulnerability in cuobjdump, where a division-by-zero error may enab

3.3
CVE-2023-25510

NVIDIA CUDA Toolkit SDK for Linux and Windows contains a NULL pointer dereference in cuobjdump, where a local user runni

3.2
CVE-2023-30618

Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform co

3.3
CVE-2023-2226

Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows att

3.5
CVE-2023-2220

A vulnerability was found in Dream Technology mica up to 3.0.5. It has been classified as problematic. Affected is an un

3.5
CVE-2023-2219

A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as problematic. This issue affects s

3.5
CVE-2023-2216

A vulnerability classified as problematic was found in Campcodes Coffee Shop POS System 1.0. Affected by this vulnerabil

3.3
CVE-2023-22846

Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a s

3.3
CVE-2023-22354

Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a spe

3.3
CVE-2023-22321

Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a speci

3.3
CVE-2023-22295

Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a speciall

3.6
CVE-2023-2112

Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.

3.5
CVE-2022-4942

A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by th

2.9
CVE-2022-38125

Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modu

2.7
CVE-2023-28440

Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a

2.4
CVE-2023-26049

Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggl

3.3
CVE-2023-22003

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affecte

3.6
CVE-2023-21999

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

3.2
CVE-2023-21991

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

3.8
CVE-2023-21988

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

3.7
CVE-2023-21968

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).

2.7
CVE-2023-21963

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions

3.7
CVE-2023-21938

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).

3.7
CVE-2023-21937

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

1.8
CVE-2023-21928

Vulnerability in the Oracle Solaris product of Oracle Systems (component: IPS repository daemon). The supported versio

2.4
CVE-2023-2155

A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This v

3.5
CVE-2023-2153

A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as problematic. Affected by t

3.5
CVE-2023-30540

Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later t

2.8
CVE-2015-10103

A vulnerability, which was classified as problematic, was found in InternalError503 Forget It up to 1.3. This affects an

3.1
CVE-2023-27525

An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods

3.7
CVE-2023-22687

Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager

3.5
CVE-2015-10101

A vulnerability classified as problematic was found in Google Analytics Top Content Widget Plugin up to 1.5.6 on WordPre

3.7
CVE-2023-29203

XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users

3.5
CVE-2023-2100

A vulnerability classified as problematic was found in SourceCodester Vehicle Service Management System 1.0. This vulner

3.5
CVE-2023-2099

A vulnerability classified as problematic has been found in SourceCodester Vehicle Service Management System 1.0. This a

3.5
CVE-2023-2098

A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been rated as problematic. Aff

3.3
CVE-2023-29383

In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger

3.5
CVE-2023-2077

A vulnerability, which was classified as problematic, has been found in Campcodes Online Traffic Offense Management Syst

3.5
CVE-2023-2076

A vulnerability classified as problematic was found in Campcodes Online Traffic Offense Management System 1.0. This vuln

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started