Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing wo
Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-w
Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <=
A vulnerability, which was classified as problematic, was found in SourceCodester Bank Management System 1.0. This affec
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in
'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may al
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab
Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0.
A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket custome
When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received
A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects
A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown p
A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this issue is some unk
A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerabilit
A vulnerability, which was classified as problematic, was found in Thomson TCW710 ST5D.10.05. Affected is an unknown fun
A vulnerability, which was classified as problematic, has been found in Thomson TCW710 ST5D.10.05. This issue affects so
IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication r
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows
A vulnerability, which was classified as problematic, was found in PHPList 3.2.6. Affected is an unknown function of the
A vulnerability, which was classified as problematic, has been found in PHPList 3.2.6. This issue affects some unknown p
A vulnerability classified as problematic was found in PHPList 3.2.6. This vulnerability affects unknown code of the fil
A vulnerability was found in PHPList 3.2.6. It has been declared as problematic. Affected by this vulnerability is an un
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. Th
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Aff
silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using t
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQ
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various
The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it
The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in
The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in vari
A vulnerability has been found in SialWeb CMS and classified as problematic. This vulnerability affects unknown code of
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart d
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local atta
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local a
Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address
Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID a
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers
Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC ad
Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigge
Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to ge
A vulnerability was found in Klapp App and classified as problematic. This issue affects some unknown processing of the
A vulnerability, which was classified as problematic, has been found in Server Status. This issue affects some unknown p
A vulnerability classified as problematic was found in Countdown Timer. This vulnerability affects unknown code of the c
A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New W
A vulnerability was found in Refined Toolkit. It has been rated as problematic. Affected by this issue is some unknown f
A vulnerability was found in PlantUML 6.43. It has been declared as problematic. Affected by this vulnerability is the c
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0be
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started