Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-ti
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v
Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the us
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames
Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati
The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses withou
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authori
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature loca
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly check
Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacke
A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_st
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute
Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi
Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff
The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid
Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l
Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote att
Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote at
Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had co
Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file
A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affec
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter
A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functional
A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/
A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of th
A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the
A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.L
A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects t
A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some
A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the functi
A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of
A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the
A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de
A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an un
7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of
A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObserv
A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started