A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of t
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Affected is an unknown function
A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype
A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry
A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elf
A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations o
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.
Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.
In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_pars
The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.
The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can lev
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a Prox
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources
A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This
A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method
A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST r
A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.
A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file
A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted elemen
A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. E
A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Inco
A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignm
A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternRe
DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and belo
HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all version
CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with admin
CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with ad
CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to vers
auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.e
Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks throug
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within t
IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by
The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers wi
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of th
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker
The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership v
A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File
A security vulnerability has been detected in Cudy TR1200 1.16.3-20230804-164635. Impacted is an unknown function of the
A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the fi
A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binuti
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started