A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnera
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a m
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker c
Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traver
H3 is a minimal H(TTP) framework. In versions 2.0.0-0 through 2.0.1-rc.16, the `mount()` method in h3 uses a simple `sta
Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to co
HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us
HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organiz
HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurren
HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo
HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s softw
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h
HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating t
A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of th
A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdo
A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functio
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from
GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.1
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A docu
This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypa
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of
A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the fi
A security flaw has been discovered in bolo-blog up to 2.6.4. The affected element is an unknown function of the file /c
A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing
A vulnerability was determined in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the
A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /w
A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/
A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpCli
A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Car
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login
A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of
A vulnerability was found in code-projects Exam Form Submission 1.0. The affected element is an unknown function of the
A vulnerability has been found in code-projects Exam Form Submission 1.0. Impacted is an unknown function of the file /a
A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPor
A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the co
A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects an unknown function of the file /cgi-bin/login
A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_si
A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits inst
The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl
OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control f
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with hos
OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling th
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started