A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file
A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::opera
The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v
The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and ac
A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the lib
A security vulnerability has been detected in ggreer the_silver_searcher up to 2.2.0. The impacted element is the functi
A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpressio
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts
IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be e
A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blosso
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially w
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If
A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Se
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issu
A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team
A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the fil
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of t
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?A
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file i
Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which
### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabl
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 2
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPad
The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 2
A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may
An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be a
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the
Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.add
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 1
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_token
A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 a
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an e
Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic
Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privileg
Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (es
A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation
A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompt
Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.
A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacke
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr
A flaw has been found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionColl
A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started