OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts cer
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts chan
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a
An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resol
An issue that could expose task information outside of the authorized organization scope has been resolved. This is an i
An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope h
An issue that could allow a user with access to a credential to view sensitive fields through an API response has been r
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `Mod
Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows D
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoin
A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of t
A flaw has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affect
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
A vulnerability was detected in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/adm
A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3
A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th
A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vuln
A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functional
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could
A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component In
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h`
A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function
A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a
A vulnerability was identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android. Impacted is an unknown function of the
A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function
A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on Android. This affects an unk
A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unkno
A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affected element is an unknown function of th
A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file
A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects s
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could l
A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the f
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache sess
A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown f
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API acce
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Son
A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functional
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file package
A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or H
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This r
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extrac
A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of t
A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send em
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started