IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1
A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the fil
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl
A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown fu
A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of
A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/
A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\v
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to dat
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security applianc
Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.2
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creatio
A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is som
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder f
OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga
When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNS
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http
An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_p
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t
A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes
A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/pack
A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA
A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file
A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c
A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of
A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the
A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/o
A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown funct
A security flaw has been discovered in Open5GS 2.7.6. This issue affects the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6
A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknow
A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown fun
A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function
A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.s
Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed
Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed
A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This l
A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unk
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started