PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Reque
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped fo
A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertT
A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web
A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Con
A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa
Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memo
AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon
Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili
OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-i
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 1
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to e
A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UP
Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s
A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown pro
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authentic
The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MO
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below co
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functi
A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file ro
A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functi
The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, w
A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file sr
A weakness has been identified in xnx3 wangmarket up to 4.9. This affects the function variableList of the file /admin/s
A security flaw has been discovered in xnx3 wangmarket up to 4.9. Affected by this issue is some unknown functionality o
A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Ba
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variabl
A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_ses
A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function ogs_gtp2_pars
A vulnerability was identified in Open5GS up to 2.7.6. Affected is the function sgwc_s11_handle_create_session_request o
A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phi
A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the
A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This a
A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application
A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that U
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buf
A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the
A weakness has been identified in zhujunliang3 work_platform up to 6bc5a50bb527ce27f7906d11ea6ec139beb79c31. This vulner
A security flaw has been discovered in sunhailin12315 product-review 商品评价系统 up to 91ead6890b4065bb45b7602d0d73348e75cb46
Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Conf
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started