A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.p
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions start
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occu
Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unaut
A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been rated as problematic. This issue aff
A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been declared as problematic. This vulner
solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A
A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function o
Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1.x 19.3.x, 19.3.0.x, 19.4.x, 19.4.0.x, 1
A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with v
Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text t
A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /ba
A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This
A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?pa
A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the
A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issu
Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sen
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of t
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access fiel
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized in
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized informa
Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moder
A logged-in and authenticated user with a Reviewer Role may lock a content item.
SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal
Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow a
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are aff
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are aff
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affe
Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are aff
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of op
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting fr
.NET Framework Denial of Service Vulnerability
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerabilit
This vulnerability arises because the application allows the user to perform some sensitive action without verifying tha
TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideo
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site reque
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint
Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook me
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on W
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2
A NULL pointer dereference flaw was found in pesign's cms_set_pw_data() function of the cms_common.c file. The function
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started