A vulnerability, which was classified as problematic, was found in generator-hottowel 0.0.11. Affected is an unknown fun
A vulnerability was found in NREL api-umbrella-web 0.7.1. It has been classified as problematic. This affects an unknown
A vulnerability was found in qt-users-jp silk 0.0.1. It has been declared as problematic. This vulnerability affects unk
A vulnerability was found in doomsider shadow. It has been classified as problematic. Affected is an unknown function. T
A vulnerability was found in madgicweb BuddyStream Plugin up to 3.2.7 on WordPress. It has been declared as problematic.
A vulnerability, which was classified as problematic, was found in cxasm notepad-- 1.22. This affects an unknown part of
A vulnerability was found in SourceCodester Simple Food Ordering System 1.0. It has been classified as problematic. This
Improper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially e
Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 m
Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to
NULL pointer dereference in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to pot
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially
Improper conditions check in the Open CAS software maintained by Intel(R) before version 22.3.1 may allow an authenticat
Cross-site scripting in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to
Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2.16.100.1 may allow an
Improper conditions check in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information
Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially ena
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet Fo
A vulnerability was found in Netgear WNDR3700v2 1.0.1.14 and classified as problematic. This issue affects some unknown
A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers
A vulnerability classified as problematic was found in PHPCrazy 1.1.1. This vulnerability affects unknown code of the fi
Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value`
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions),
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions),
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not
A vulnerability was found in juju2143 WalrusIRC 0.0.2. It has been rated as problematic. This issue affects the function
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne
A vulnerability was found in UDX Stateless Media Plugin 3.1.1 on WordPress. It has been declared as problematic. This vu
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is
A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as pr
A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects
A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on W
A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vuln
Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated atta
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability.
Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated
PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerabil
Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner&#
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
Improper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision.
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptogr
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this
A vulnerability was found in Custom-Content-Width 1.0. It has been declared as problematic. Affected by this vulnerabili
A vulnerability was found in OpenSeaMap online_chart 1.2. It has been classified as problematic. Affected is the functio
Nextcloud mail is an email app for the nextcloud home server platform. In versions prior to 2.2.2 user's passwords were
A vulnerability, which was classified as problematic, has been found in WangGuard Plugin 1.8.0 on WordPress. Affected by
A vulnerability, which was classified as problematic, was found in tinymighty WikiSEO 1.2.1 on MediaWiki. This affects t
A vulnerability classified as problematic has been found in eXo Chat Application. Affected is an unknown function of the
A vulnerability classified as problematic was found in ciubotaru share-on-diaspora 0.7.9. This vulnerability affects unk
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started