A vulnerability was found in Dalli up to 3.2.2. It has been classified as problematic. Affected is the function self.met
Multiple Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilities in Accordions plugin <= 2.0.3 on WordPress via
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version
Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.
A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicaliz
A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedI
A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePassw
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function
A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delet
Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account a
Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permi
Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account
Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permiss
Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to in
Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account
Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permission
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a loc
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used b
A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this v
A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functional
A vulnerability, which was classified as problematic, has been found in NukeViet CMS. Affected by this issue is the func
A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function g
A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown func
A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the fi
CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.
A vulnerability, which was classified as problematic, has been found in drogon up to 1.8.1. Affected by this issue is so
Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an
Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable
Premature release of resource during expected lifetime in the Intel(R) SGX SDK software may allow a privileged user to p
Improper buffer restrictions in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow
A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerabil
A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink
A vulnerability, which was classified as problematic, has been found in Sourcecodester Simple Cashiering System. This is
A vulnerability was found in ForU CMS. It has been classified as problematic. Affected is an unknown function of the fil
A vulnerability, which was classified as problematic, was found in lanyulei ferry. This affects an unknown part of the f
Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri
Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's C API implementat
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates u
An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4,
Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5
An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior
Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 all
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep op
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI pack
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started