Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly
Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default impl
FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-cha
A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, pot
A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() functi
A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsi
Vulnerability in the Oracle Zero Data Loss Recovery Appliance Software product of Oracle Zero Data Loss Recovery Applian
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that
Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supporte
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver setti
IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau
IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to s
A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the fil
A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/get
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable pas
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensit
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKno
A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the fil
A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the c
A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affect
A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affect
A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the functio
A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in t
A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of t
A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?A
The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs u
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be ab
Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authentica
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site
A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modificatio
A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us
Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the s
A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4,
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to
The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographi
Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started