A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Das
A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST paramete
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting character
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment,
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.1
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.1,
A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the fil
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from th
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vuln
Microsoft Power BI Spoofing Vulnerability
Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1
Hard-coded credentials in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplu
SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option.
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allow
A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by explo
The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information.
The affected product is vulnerable due to an invalid pointer initialization, which may lead to information disclosure.
Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to acce
Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows a
Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently laun
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched
Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEG
Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access se
Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior
Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20.
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versio
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom impleme
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions start
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 p
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting f
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DO
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started