Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 54/162
3.1
CVE-2025-10320

A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the f

3.5
CVE-2025-27238

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user gr

3.5
CVE-2025-3650

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes o

3.1
CVE-2025-10287

A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element

3.5
CVE-2025-10273

A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the f

3.8
CVE-2025-56556

An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the buil

3.5
CVE-2025-10255

A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the fi

3.5
CVE-2025-10254

A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of

3.5
CVE-2025-10253

A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifi

3.1
CVE-2025-10252

A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI

3.5
CVE-2025-10246

A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b

3.1
CVE-2025-6088

In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow una

2.4
CVE-2025-10235

A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm o

2.4
CVE-2025-10234

A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point

2.6
CVE-2025-10216

A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout

3.3
CVE-2025-10222

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon

3.1
CVE-2025-8277

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guess

2.7
CVE-2025-59014

An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 l

3.1
CVE-2025-40803

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes ce

3.1
CVE-2025-40802

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be sus

3.5
CVE-2025-9111

The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which cou

3.8
CVE-2025-8889

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege u

3.4
CVE-2025-42927

SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful

3.1
CVE-2025-42914

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in

3.1
CVE-2025-42913

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in

3.5
CVE-2025-10117

A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi

3.7
CVE-2024-48341

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.

2.4
CVE-2025-10099

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona

3.7
CVE-2025-51586

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers

3.5
CVE-2025-10088

A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file

3.1
CVE-2025-58422

RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perfor

3.1
CVE-2025-10080

A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTok

3.5
CVE-2025-10075

A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown func

3.5
CVE-2025-10074

A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the fil

3.3
CVE-2025-0011

Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to ob

3.2
CVE-2024-36331

Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SN

3.9
CVE-2023-31365

An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reser

2.5
CVE-2023-31330

An out-of-bounds read in the ASP could allow a privileged attacker with access to a malicious bootloader to potentially

2.8
CVE-2023-31326

Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution env

3.3
CVE-2023-31306

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed argu

3.3
CVE-2023-20516

Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Reg

3.0
CVE-2021-46750

Failure to validate the address and size in TEE (Trusted Execution Environment) may allow a malicious x86 attacker to se

3.5
CVE-2025-10029

A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown cod

3.5
CVE-2025-10028

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /i

3.8
CVE-2025-57807

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lowe

3.5
CVE-2025-10027

A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown func

3.5
CVE-2025-10026

A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown fun

3.1
CVE-2025-10014

A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/upda

3.3
CVE-2025-26461

In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the u

2.7
CVE-2025-58866

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami Yushuvaev Site Info sit

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started