Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 50/162
2.1
CVE-2025-59294

Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to di

3.3
CVE-2025-59284

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp

3.1
CVE-2025-59280

Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.

2.7
CVE-2025-58903

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API a

2.6
CVE-2025-47890

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, Fo

2.7
CVE-2025-31514

A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 al

3.5
CVE-2025-40773

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a

3.8
CVE-2025-8594

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could a

3.1
CVE-2025-11731

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during sty

3.0
CVE-2025-42909

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default p

3.5
CVE-2025-62178

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a Reflec

3.5
CVE-2025-62174

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.2

3.5
CVE-2025-58084

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing

3.5
CVE-2025-31995

HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities

1.8
CVE-2025-11650

A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the f

3.1
CVE-2025-11647

A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component G

2.4
CVE-2025-11645

A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown

2.0
CVE-2025-11644

A weakness has been identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is some unknown functionality

3.7
CVE-2025-11643

A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. Affected by this vulnerability is an unknown fu

3.9
CVE-2025-11641

A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Tr

3.1
CVE-2025-11640

A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function of the component Bluetoo

3.3
CVE-2025-11639

A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the f

3.5
CVE-2025-2139

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the networ

3.5
CVE-2025-2138

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the netw

2.4
CVE-2025-11634

A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. This affects an unknown part of the component U

3.7
CVE-2025-11633

A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_t

3.5
CVE-2025-52615

HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser def

3.5
CVE-2025-52614

HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to in

3.5
CVE-2025-31998

HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information.

3.5
CVE-2025-31993

HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can

3.7
CVE-2025-11609

A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component

2.4
CVE-2025-8606

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less

3.3
CVE-2025-58292

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av

3.3
CVE-2025-58291

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av

3.3
CVE-2025-58290

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av

3.3
CVE-2025-58286

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av

2.8
CVE-2025-58282

Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service

3.7
CVE-2025-52635

A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION:

3.7
CVE-2025-52625

A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose cre

3.7
CVE-2025-52634

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

3.7
CVE-2025-52630

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

3.1
CVE-2025-52655

Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-part

2.4
CVE-2025-21046

Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to tem

2.7
CVE-2025-4614

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to

3.3
CVE-2025-11495

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of

3.3
CVE-2025-11494

A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd

2.4
CVE-2025-11485

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user

3.7
CVE-2025-11443

A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/passwor

3.7
CVE-2025-11441

A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the compon

2.4
CVE-2025-11437

A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the c

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started