Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

3,107
Total
Showing 2,090 of 3,107 total · Page 3/42
2.5
CVE-2026-71514

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the c

2.7
CVE-2026-14187

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al

3.5
CVE-2026-33333

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the

3.5
CVE-2026-69238

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly

3.8
CVE-2026-69237

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker

3.7
CVE-2026-18356

The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist ca

2.7
CVE-2026-13176

The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify eve

2.7
CVE-2026-66721

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by def

2.7
CVE-2026-19435

The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allo

2.7
CVE-2026-19085

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplic

2.7
CVE-2026-16577

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a c

3.5
CVE-2026-14325

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its set

3.3
CVE-2026-76137

Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local

2.4
CVE-2026-43679

This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physi

2.2
CVE-2026-77648

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allow

3.7
CVE-2026-49245

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on bro

3.7
CVE-2026-77640

tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncat

3.7
CVE-2026-77151

A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of t

3.7
CVE-2026-49996

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se

2.8
CVE-2026-64846

Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the rec

2.4
CVE-2026-18283

Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attacker

3.9
CVE-2026-18280

Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically presen

3.5
CVE-2026-18278

Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows

3.7
CVE-2026-73542

Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an at

2.7
CVE-2026-19699

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoint

3.1
CVE-2026-76926

BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

3.1
CVE-2026-76891

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

3.1
CVE-2026-76890

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

3.1
CVE-2026-76888

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

3.1
CVE-2026-76887

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

3.1
CVE-2026-76885

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

3.1
CVE-2026-76884

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

2.7
CVE-2026-76371

In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could r

2.7
CVE-2026-76369

In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Auto

2.7
CVE-2026-76368

In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view meta

2.7
CVE-2026-76361

In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../c

3.8
CVE-2026-76348

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the

3.1
CVE-2026-75476

Tanium addressed a compression bomb vulnerability in Threat Response.

3.5
CVE-2026-18102

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer

3.1
CVE-2026-11617

Tanium addressed a compression bomb vulnerability in Findings.

3.3
CVE-2026-16891

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out

3.6
CVE-2026-16890

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a de

3.7
CVE-2026-16888

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a pat

3.5
CVE-2026-75583

keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerab

3.3
CVE-2026-49423

When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index

3.3
CVE-2026-49431

The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is

3.3
CVE-2026-49426

When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup f

2.7
CVE-2026-19406

The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to t

2.7
CVE-2026-14826

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the RE

2.7
CVE-2026-14825

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before sa

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 3,107 CVE records rated LOW in our database.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started