A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unkno
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.
A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affect
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attacker
Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content provid
Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read
Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of co
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `tru
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPres
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows
Dell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unaut
readelf in ToaruOS 2.0.1 has some arbitrary address read vulnerabilities when parsing a crafted ELF file.
A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic. This vulnerability affects unknown
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was disco
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwa
A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an un
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0
A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk i
Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress.
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded w
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <=
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when l
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio
User input included in error response, which could be used in a phishing attack.
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A perso
Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud
Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webse
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links vi
Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro
In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vul
Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation se
Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could poten
Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with phy
Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator us
Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated a
Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potenti
Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could poten
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG image
Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via
Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global an
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started