Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_deta
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/adm
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/ma
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/a
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a
Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php
Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category
Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/
Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/e
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php.
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php.
A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.
Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. Use
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create f
Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden not
A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of
UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect avai
Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may
Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affe
A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/commo
A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddl
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host c
phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\N
TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. Th
Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to befor
OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against c
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p em
A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/icon
A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unkn
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted applic
Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prio
Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied sys
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which all
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which all
A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functional
A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality
A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 1
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /del
A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter
Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Re
Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-ti
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5,
Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started