A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the f
Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user gr
The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes o
A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element
A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the f
An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the buil
A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the fi
A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of
A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifi
A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI
A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b
In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow una
A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm o
A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point
A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon
A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guess
An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 l
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes ce
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be sus
The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which cou
The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege u
SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in
A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers
A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file
RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perfor
A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTok
A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown func
A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the fil
Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to ob
Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SN
An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reser
An out-of-bounds read in the ASP could allow a privileged attacker with access to a malicious bootloader to potentially
Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution env
Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed argu
Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Reg
Failure to validate the address and size in TEE (Trusted Execution Environment) may allow a malicious x86 attacker to se
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown cod
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /i
ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lowe
A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown func
A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown fun
A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/upda
In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the u
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami Yushuvaev Site Info sit
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started