Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 48/162
3.3
CVE-2025-31948

Improper input validation for some Intel(R) oneAPI Math Kernel Library before version 2025.2 within Ring 3: User Applica

3.8
CVE-2025-30509

Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applic

3.3
CVE-2025-25216

Improper input validation in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic

2.0
CVE-2025-24862

Unrestricted upload of file with dangerous type for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within

2.2
CVE-2025-24314

Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicatio

2.0
CVE-2025-24307

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl

3.8
CVE-2025-20622

Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before ve

2.7
CVE-2025-64773

In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

3.4
CVE-2025-13015

Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.

3.1
CVE-2025-8998

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and i

2.7
CVE-2025-42883

Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an

3.5
CVE-2025-62780

changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in cha

2.7
CVE-2025-64682

In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit

2.7
CVE-2025-64681

In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

2.7
CVE-2025-12923

A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownl

2.4
CVE-2025-12920

A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the fil

3.7
CVE-2025-12919

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graph

3.1
CVE-2025-12918

A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an u

3.7
CVE-2025-12854

A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill o

3.7
CVE-2025-48985

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have

3.1
CVE-2025-11219

Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bou

2.6
CVE-2025-64326

Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project membe

3.3
CVE-2025-21077

Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity

3.3
CVE-2025-43442

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS

2.0
CVE-2025-43423

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.

2.4
CVE-2025-43408

This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.7.2,

3.3
CVE-2025-43395

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1

2.8
CVE-2025-43365

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.

2.4
CVE-2025-43350

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An atta

2.4
CVE-2025-43309

A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical

3.1
CVE-2025-12623

A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this iss

3.7
CVE-2025-12616

A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onp

3.7
CVE-2025-12547

A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of t

3.5
CVE-2025-12546

A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen

3.7
CVE-2025-36249

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or se

2.7
CVE-2025-64352

Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite al

3.8
CVE-2025-64350

Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Config

3.1
CVE-2025-23050

QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (o

3.5
CVE-2025-10636

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which c

3.8
CVE-2025-10931

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analy

3.5
CVE-2025-11203

LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to d

3.0
CVE-2025-56558

The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct v

3.8
CVE-2025-62794

GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced s

3.7
CVE-2025-10939

A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the install

2.4
CVE-2025-12332

A flaw has been found in SourceCodester Student Grades Management System 1.0. This affects the function delete_user of t

2.4
CVE-2025-12330

A security flaw has been discovered in Willow CMS up to 1.4.0. This issue affects some unknown processing of the file /a

2.4
CVE-2025-12312

A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file vie

2.4
CVE-2025-12311

A vulnerability was detected in PHPGurukul Curfew e-Pass Management System 1.0. This issue affects some unknown processi

2.4
CVE-2025-12303

A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of

2.4
CVE-2025-12282

A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function o

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started