Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

3,107
Total
Showing 2,090 of 3,107 total · Page 2/42
3.9
CVE-2026-21807

HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow

3.7
CVE-2025-62341

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allo

3.9
CVE-2026-21809

HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when i

3.5
CVE-2026-77573

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

3.5
CVE-2026-77508

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email

3.5
CVE-2026-56547

The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler

3.7
CVE-2026-47843

In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrect

3.3
CVE-2026-54548

kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH

3.1
CVE-2026-13480

The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/f

3.1
CVE-2026-13479

The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lo

3.5
CVE-2026-7487

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3

3.7
CVE-2026-19220

The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network be

2.7
CVE-2026-9805

SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size

2.0
CVE-2026-80201

Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call

3.7
CVE-2026-80199

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers t

3.1
CVE-2026-79272

Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro

3.1
CVE-2026-79255

Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise

3.1
CVE-2026-79228

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr

3.1
CVE-2026-79203

Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromi

3.1
CVE-2026-79191

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr

3.1
CVE-2026-79103

Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr

3.1
CVE-2026-79066

Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro

3.1
CVE-2026-79059

Information leak in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re

3.1
CVE-2026-79053

Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise

3.1
CVE-2026-79034

Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende

3.1
CVE-2026-79031

Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site i

3.1
CVE-2026-79002

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr

3.1
CVE-2026-78953

Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had comprom

2.9
CVE-2026-78949

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o

3.1
CVE-2026-78943

Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

2.9
CVE-2026-78936

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o

3.1
CVE-2026-78903

Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise

3.1
CVE-2026-78894

Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the ren

3.3
CVE-2026-43657

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malic

3.6
CVE-2026-79783

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local back

3.1
CVE-2026-79782

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTT

2.7
CVE-2026-79777

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger p

3.5
CVE-2026-70548

Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External De

2.9
CVE-2025-71346

Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-

3.7
CVE-2026-78887

A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of th

3.7
CVE-2026-78886

A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/s

3.7
CVE-2026-21758

HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive inf

3.3
CVE-2026-78638

A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dis

3.7
CVE-2026-72701

Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string compar

3.8
CVE-2026-78435

A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Contr

3.5
CVE-2026-76816

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final,

3.1
CVE-2026-78187

A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication

3.7
CVE-2026-19565

Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock

2.7
CVE-2026-77003

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being c

3.7
CVE-2026-78049

A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVar

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 3,107 CVE records rated LOW in our database.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started