Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 53/162
3.1
CVE-2025-10778

A vulnerability has been found in Smartstore up to 6.2.0. The affected element is an unknown function of the file /check

3.7
CVE-2025-10776

A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the co

3.7
CVE-2025-10761

A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api/v1/login of the compon

2.4
CVE-2025-10758

A security vulnerability has been detected in htmly up to 3.1.0. The impacted element is an unknown function of the file

3.1
CVE-2025-9081

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authe

3.7
CVE-2025-59692

PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing ipta

3.7
CVE-2025-59691

PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon netwo

3.7
CVE-2025-10671

A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of t

3.7
CVE-2025-4444

A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Oni

3.7
CVE-2025-30187

In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries,

3.5
CVE-2025-10642

A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts

3.5
CVE-2025-10632

A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unk

3.5
CVE-2025-10631

A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of

3.7
CVE-2025-59410

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the s

3.3
CVE-2025-59349

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, DragonFly2 uses t

3.1
CVE-2025-59414

Nuxt is an open-source web development framework for Vue.js. Prior to 3.19.0 and 4.1.0, A client-side path traversal vul

3.5
CVE-2025-10591

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet

3.5
CVE-2025-10584

A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/

2.2
CVE-2025-30075

In Alludo MindManager before 25.0.208 on Windows, attackers could potentially execute code as other local users on the s

3.1
CVE-2025-59270

psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML au

3.5
CVE-2025-26710

There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control me

3.2
CVE-2025-59453

Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency acce

3.2
CVE-2025-59437

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly catego

3.2
CVE-2025-59436

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improp

3.3
CVE-2025-43357

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18

2.8
CVE-2025-43349

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7 and iPadOS 18

3.3
CVE-2025-43344

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26,

3.3
CVE-2025-43328

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl

3.3
CVE-2025-43301

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia

3.3
CVE-2025-43294

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue

3.3
CVE-2025-43283

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be

3.1
CVE-2025-59399

libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error me

3.1
CVE-2025-59398

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 2

3.7
CVE-2025-59377

feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl beca

3.7
CVE-2025-59376

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ

3.1
CVE-2025-9084

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to

2.4
CVE-2025-10434

A vulnerability was identified in IbuyuCMS up to 2.6.3. Impacted is an unknown function of the file /admin/article.php?a

3.7
CVE-2025-10423

A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file /common/mall/kaptcha. The

2.3
CVE-2025-0164

IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unautho

3.5
CVE-2025-10388

A vulnerability was identified in Selleo Mentingo 2025.08.27. This issue affects some unknown processing of the file /ap

3.5
CVE-2025-10373

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown functio

3.5
CVE-2025-10372

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/

3.5
CVE-2025-10370

A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the

3.5
CVE-2025-10369

A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdoc

3.5
CVE-2025-10368

A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality

3.5
CVE-2025-10367

A vulnerability has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown fu

3.5
CVE-2025-10366

A flaw has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/inc.

3.5
CVE-2025-10340

A vulnerability was determined in WhatCD Gazelle up to 63b337026d49b5cf63ce4be20fdabdc880112fa3. The affected element is

3.5
CVE-2025-10332

A vulnerability was found in cdevroe unmark up to 1.9.3. Impacted is an unknown function of the file application/views/m

3.5
CVE-2025-10331

A vulnerability has been found in cdevroe unmark up to 1.9.3. This issue affects some unknown processing of the file /ap

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started