A vulnerability classified as problematic has been found in DaSchTour matomo-mediawiki-extension up to 2.4.2 on MediaWik
A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the func
A vulnerability classified as problematic was found in NREL api-umbrella-web 0.7.1. This vulnerability affects unknown c
A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processi
A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affe
A vulnerability was found in TRENDnet TEW-652BRP 3.04b01 and classified as problematic. This issue affects some unknown
All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity
A vulnerability, which was classified as problematic, was found in SiteFusion Application Server up to 6.6.6. This affec
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the r
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal service
A vulnerability was found in mosbth cimage up to 0.7.18. It has been declared as problematic. Affected by this vulnerabi
A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an
A vulnerability has been found in SourceCodester Canteen Management System 1.0 and classified as problematic. This vulne
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects a
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `b
A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 all
A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unk
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After success
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After success
A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29
A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability a
The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manag
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to deter
IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptogra
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments
A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects
A vulnerability was found in MyCMS. It has been classified as problematic. This affects the function build_view of the f
Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware
Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware
A vulnerability classified as problematic has been found in GENI Portal. This affects the function no_invocation_id_erro
A vulnerability was found in GENI Portal. It has been rated as problematic. Affected by this issue is some unknown funct
A vulnerability was found in melnaron mel-spintax. It has been rated as problematic. Affected by this issue is some unkn
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Sound). Su
A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuth
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiratio
A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the
A vulnerability has been found in s134328 Webapplication-Veganguide and classified as problematic. This vulnerability af
A vulnerability, which was classified as problematic, was found in Wikisource Category Browser. This affects an unknown
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in simplesamlphp simplesamlphp-module-openidprovider up to 0.8
A vulnerability was found in saemorris TheRadSystem. It has been classified as problematic. Affected is an unknown funct
The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers t
A vulnerability was found in Overdrive Eletrônica course-builder up to 1.7.x and classified as problematic. Affected by
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started