A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /
A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the
A vulnerability has been found in code-projects Client Details System 1.0. This vulnerability affects unknown code of th
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging
A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unkno
A security flaw has been discovered in Wisencode up to 20251012. Affected by this vulnerability is an unknown functional
A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI.
A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown functi
A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the f
A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of
A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown functi
A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown func
A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerabili
A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the c
A flaw has been found in Kamailio 5.5. The impacted element is the function rve_is_constant of the file src/core/rvalue.
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that
GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable
The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all version
Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model r
The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate pa
A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralizat
On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.
Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.
On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The sup
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The suppor
Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). Supported versions that ar
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-2
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected a
A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeer
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected b
Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affe
A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process
A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the compo
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in
LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-
radare2 v5.9.8 and before contains a memory leak in the function bochs_open.
LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules p
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and
A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set
A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. E
A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Perf
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding c
Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace e
Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application u
An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could all
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabli
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started