A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown function of the file aedes/m
A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function
A vulnerability was determined in UEditor up to 1.4.3.2. This issue affects some unknown processing of the file php/cont
A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file
A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/
A security flaw has been discovered in Tecnick TCExam up to 16.6.0. Affected is the function F_xml_export_users of the f
A vulnerability was identified in Tecnick TCExam 16.5.0. This impacts an unknown function of the file /admin/code/tce_ed
A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi
A vulnerability has been found in Worksuite HR, CRM and Project Management up to 5.5.25. The affected element is an unkn
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memo
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the back
Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attack
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver
in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).
Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforc
Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Confi
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache
wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipie
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi
A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php
A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.
A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the c
A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated u
A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. The impacted element is the fun
A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. The affected eleme
A vulnerability has been found in jarikomppa soloud up to 20200207. Impacted is the function drwav_read_pcm_frames_s16__
A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerab
A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This aff
A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function rememberMeManager o
Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to
HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by defa
Copyparty is a portable file server. Prior to 1.20.12, if an attacker has been given both read- and write-permissions to
A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could all
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file lib
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (P
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerabil
A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the fil
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A l
Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1
A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started