Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 49/162
2.4
CVE-2025-12281

A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /

2.4
CVE-2025-12280

A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the

2.4
CVE-2025-12279

A vulnerability has been found in code-projects Client Details System 1.0. This vulnerability affects unknown code of th

3.2
CVE-2025-11248

ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging

3.5
CVE-2025-12269

A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unkno

3.5
CVE-2025-12264

A security flaw has been discovered in Wisencode up to 20251012. Affected by this vulnerability is an unknown functional

3.5
CVE-2025-12251

A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI.

2.4
CVE-2025-12231

A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown functi

2.4
CVE-2025-12230

A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the f

2.4
CVE-2025-12229

A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of

2.4
CVE-2025-12228

A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown functi

3.5
CVE-2025-12227

A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown func

3.5
CVE-2025-12224

A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerabili

3.3
CVE-2025-12207

A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the c

3.3
CVE-2025-12206

A flaw has been found in Kamailio 5.5. The impacted element is the function rve_is_constant of the file src/core/rvalue.

2.7
CVE-2025-6601

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that

3.7
CVE-2025-11989

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18

2.7
CVE-2025-11888

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable

3.7
CVE-2025-11244

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all version

3.1
CVE-2025-62711

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model r

2.7
CVE-2025-10723

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate pa

2.7
CVE-2025-41721

A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralizat

3.1
CVE-2025-62774

On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.

2.4
CVE-2025-62773

Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.

3.1
CVE-2025-62772

On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.

2.7
CVE-2025-62480

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The sup

2.7
CVE-2025-62479

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The suppor

3.7
CVE-2025-61755

Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). Supported versions that ar

2.7
CVE-2025-61749

Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-2

3.7
CVE-2025-61748

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

2.7
CVE-2025-53051

Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected a

3.3
CVE-2022-4981

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeer

3.3
CVE-2025-5496

ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected b

2.9
CVE-2025-57837

Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affe

3.5
CVE-2025-11946

A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process

3.5
CVE-2025-11945

A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the compo

3.4
CVE-2025-62643

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in

3.0
CVE-2025-62505

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-

3.3
CVE-2025-60361

radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

3.8
CVE-2025-62412

LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules p

3.8
CVE-2025-61924

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and

3.5
CVE-2025-11851

A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set

3.3
CVE-2025-11840

A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. E

3.3
CVE-2025-11839

A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Perf

3.1
CVE-2025-54499

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp

3.1
CVE-2025-10545

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding c

3.1
CVE-2025-62379

Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace e

2.9
CVE-2025-2529

Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application u

3.1
CVE-2025-6026

An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could all

2.2
CVE-2025-56746

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabli

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started