ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage
ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding pat
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept
Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain r
Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization secur
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene
There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co
HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
The github_workflows module constructs local directory paths from user-controlled repository names without validating fo
The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authent
Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-con
snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or No
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinc
In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v
In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to l
In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information
In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could
In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic erro
In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to
In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote informa
In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the pac
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArg
A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of
A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functional
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing h
The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and o
OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to va
ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyU
A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of t
A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown
A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown
The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some o
Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had co
OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr
Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b
A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, an
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started