The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting
The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory wit
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. Th
The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result
The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is speci
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp,
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and
A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via eith
PRSD detection denial of service
A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directo
Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or
Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
Tanium addressed an information disclosure vulnerability in Tanium Server.
Tanium addressed an information disclosure vulnerability in Threat Response.
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin acc
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events)
Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t
A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of th
A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar.
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in
October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission c
October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Script
HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise wh
PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availab
OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` i
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authen
A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of
A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component I
A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file pl
A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the fil
A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of t
A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the fi
A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/ap
A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangob
The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow hi
A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of
A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_ter
A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file serv
A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of th
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started