Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure met
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accesse
Raidrive before v2021.12.35 allows attackers to arbitrarily move log files by pre-creating a mountpoint and log files be
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead
A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly n
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Pr
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profel
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of s
A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typic
A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profil
A vulnerability was found in DolphinPHP up to 1.5.0 and classified as problematic. Affected by this issue is the User Ma
A vulnerability was found in CLTPHP up to 6.0. It has been declared as problematic. Affected by this vulnerability is th
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue
A vulnerability, which was classified as problematic, was found in WEKA INTEREST Security Scanner up to 1.8. This affect
A vulnerability, which was classified as problematic, has been found in WEKA INTEREST Security Scanner up to 1.8. Affect
A vulnerability classified as problematic was found in WEKA INTEREST Security Scanner up to 1.8. Affected by this vulner
A vulnerability classified as problematic has been found in WEKA INTEREST Security Scanner up to 1.8. Affected is Stress
A vulnerability was found in WEKA INTEREST Security Scanner 1.8. It has been rated as problematic. This issue affects so
A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerabi
An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigg
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting fr
A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since re
A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Af
Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single characte
Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malici
Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO)
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. Th
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed
Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code cou
An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 1
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 an
An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadO
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the syste
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, wh
In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project
Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the share
The package node-lmdb before 0.9.7 are vulnerable to Denial of Service (DoS) when defining a non-invokable ToString valu
A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtq
Adobe Character Animator version 4.4 (and earlier versions) are affected by an out-of-bounds read vulnerability that cou
Adobe Character Animator version 4.4 (and earlier versions) are affected by an out-of-bounds read vulnerability that cou
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could a
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but
Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access pa
Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access pa
Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access pas
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started