HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow
HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allo
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when i
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler
In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrect
kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH
The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/f
The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lo
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3
The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network be
SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call
Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers t
Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro
Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr
Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromi
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr
Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr
Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro
Information leak in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re
Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende
Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site i
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr
Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had comprom
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o
Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the ren
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malic
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local back
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTT
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger p
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External De
Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of th
A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/s
HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive inf
A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dis
Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string compar
A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Contr
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final,
A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication
Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock
The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being c
A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVar
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 3,107 CVE records rated LOW in our database.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started