Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulne
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was po
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data
Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access
Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attacke
A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability i
A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function
A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of
A vulnerability was found in y_project RuoYi-Cloud. It has been rated as problematic. Affected by this issue is some unk
A vulnerability was found in xiandafu beetl-bbs. It has been declared as problematic. Affected by this vulnerability is
A vulnerability has been found in csliuwy coder-chain_gdut and classified as problematic. Affected by this vulnerability
Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allo
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi JP1/Automatic Operation allows loc
A vulnerability classified as problematic has been found in SourceCodester Human Resource Management System 1.0. Affecte
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permi
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no pas
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths ar
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database conten
A vulnerability was found in SourceCodester Canteen Management System. It has been declared as problematic. This vulnera
A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affec
A vulnerability was found in Movie Ticket Booking System and classified as problematic. Affected by this issue is some u
A vulnerability has been found in Movie Ticket Booking System and classified as problematic. Affected by this vulnerabil
A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown f
A vulnerability was found in SourceCodester Canteen Management System. It has been rated as problematic. This issue affe
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to rea
A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as problematic. Affected b
The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.
RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password. An unauthenticated physical attacker can use the hard-c
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlim
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-lik
Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the rece
Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit u
user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery u
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless serv
A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affec
Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple reques
A vulnerability found in the OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an
IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.
A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_
A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started