Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 5/162
3.1
CVE-2026-64782

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10

3.1
CVE-2026-64779

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10

3.3
CVE-2026-75483

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt

3.6
CVE-2026-75052

In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in truste

3.3
CVE-2026-56089

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l

3.5
CVE-2026-70412

Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readab

3.7
CVE-2026-74887

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of op

3.6
CVE-2026-74885

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after cl

3.3
CVE-2026-74870

openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hs

3.3
CVE-2026-49306

UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect ava

3.5
CVE-2026-19995

A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account

3.1
CVE-2026-19992

A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome.

3.1
CVE-2026-19975

A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file ap

3.7
CVE-2026-19965

A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordRe

3.5
CVE-2026-19955

A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component T

3.1
CVE-2026-74797

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing malic

3.5
CVE-2026-19922

A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown

3.5
CVE-2026-19916

A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function

3.7
CVE-2026-19906

A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the

2.4
CVE-2026-19904

A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the

3.7
CVE-2026-19898

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmau

3.7
CVE-2026-19897

A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/a

3.7
CVE-2026-19896

A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the fi

3.7
CVE-2026-19895

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::in

3.1
CVE-2026-19893

A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf

3.7
CVE-2026-19891

A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.

3.7
CVE-2026-73844

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream respon

3.1
CVE-2026-19841

A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of th

2.7
CVE-2026-19837

A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/

3.8
CVE-2026-19835

A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality

3.8
CVE-2026-19763

A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory

3.7
CVE-2026-19749

A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20

3.7
CVE-2026-19748

A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC

3.1
CVE-2026-17074

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

2.7
CVE-2026-17071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traver

3.8
CVE-2026-17043

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal

2.7
CVE-2026-58511

Webhook Authorization Header Returned in Plaintext via API

2.7
CVE-2026-58445

Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

2.7
CVE-2026-55984

Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

3.1
CVE-2026-23603

Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

3.1
CVE-2026-73575

In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange W

3.1
CVE-2026-73574

In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Clie

3.1
CVE-2026-73573

In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document edi

3.1
CVE-2026-73571

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization

3.7
CVE-2025-62318

HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages

3.4
CVE-2025-62315

HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validatio

3.8
CVE-2026-6469

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics

3.8
CVE-2026-16241

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service again

3.8
CVE-2026-14673

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary

3.7
CVE-2026-14213

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated em

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started