Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plug
A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to
IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. T
Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and
This vulnerability allows local attackers to disclose sensitive information on affected installations of TeamViewer. An
Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (componen
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Install). The supported version that is affect
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serializati
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 a
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk la
Wagtail is a Django based content management system focused on flexibility and user experience. When notifications for n
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making qu
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log
Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows auth
Jimoty App for Android versions prior to 3.7.42 uses a hard-coded API key for an external service. By exploiting this vu
Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds read vulnerabi
Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an use-after-free vulnerability
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
Adobe Illustrator versions 25.4.2 (and earlier) and 26.0.1 (and earlier) are affected by an out-of-bounds read vulnerabi
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 1
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 1
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 1
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started