A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library sr
A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/cor
A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/o
A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef
A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /syst
A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown
A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the
A weakness has been identified in code-projects for Plugin 1.0. This affects an unknown part of the file /Administrator/
A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. Thi
A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/sav
A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown
A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the fil
A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::
A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by th
A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the f
OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injec
A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona
Tanium addressed a denial of service vulnerability in Tanium Client.
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1
A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/
A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c
A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrap
A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file w
Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTT
Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTT
Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exp
A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform
Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
Tanium addressed an improper input validation vulnerability in Tanium Appliance.
Tanium addressed an improper access controls vulnerability in Interact.
P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed
P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform admi
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp
Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7
IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using com
IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about o
IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using spec
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error mes
A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access
Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security G
A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may
IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user
Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensiti
HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow
HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow au
HCL AION is susceptible to Missing Content-Security-Policy. An The absence of a CSP header may increase the risk of cr
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect
A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started