fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discu
NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulner
Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, We
Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of pr
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could all
The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerabil
A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected
In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was misse
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
In Pandora FMS v7.0NG.761 and below, in the agent creation section, the alias parameter is vulnerable to a Stored Cross
In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at
Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows atta
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plu
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: General/Core Client). Supported versions tha
Vulnerability in the Oracle Database - Enterprise Edition RDBMS Security component of Oracle Database Server. Supported
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extensio
A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vul
In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. Th
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Parking Management System 1.0.
A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Parking Management System
A vulnerability classified as problematic was found in SourceCodester Simple Sales Management System 1.0. Affected by th
A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an u
Nautilus treadmills T616 S/N 100672PRO21140001 through 100672PRO21171980 and T618 S/N 100647PRO21130111 through 100647PR
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to cal
Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker
Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to acces
Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows l
Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid v
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started