A vulnerability was found in EyouCms up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is
A vulnerability was found in EyouCms 1.5.4. It has been classified as problematic. Affected is an unknown function of th
A vulnerability has been found in Campcodes Advanced Online Voting System 1.0 and classified as problematic. This vulner
A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects
The Android version of pikpak v1.29.2 was discovered to contain an information leak via the debug interface.
Microsoft Edge (Chromium-based) Tampering Vulnerability
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocat
An issue was discovered in the Arm Mali Kernel Driver. A non-privileged user can make improper GPU memory processing ope
The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the
A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic. Affected
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiA
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized att
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP
SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for ga
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2. A user with phy
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16. A person with physical access to
A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2
A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected
A vulnerability was found in Fancy Gallery Plugin 1.5.12 on WordPress. It has been declared as problematic. Affected by
A vulnerability was found in Turante Sandbox Theme up to 1.5.2. It has been classified as problematic. This affects the
A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected
A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this
A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been classified as problematic.
A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. It has been rated as problematic. Aff
A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0.
A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic. This issue affe
A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. Affected by this vulnerability is
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing
An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 b
An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and
An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting f
GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.
A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPres
A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28. It has been declared as problematic. This vulnerability af
A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic. Affected
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Payroll System 1.0. This i
A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0. This vulnerability affe
A vulnerability classified as problematic has been found in SourceCodester Online Payroll System 1.0. This affects an un
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue af
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Dat
Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4,
All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate fu
A vulnerability, which was classified as problematic, was found in EyouCMS up to 1.5.4. This affects an unknown part of
A vulnerability, which was classified as problematic, has been found in EyouCMS up to 1.5.4. Affected by this issue is s
A vulnerability classified as problematic has been found in SourceCodester Employee Payslip Generator 1.0. Affected is a
A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been rated as problematic. T
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started