Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 56/162
3.5
CVE-2025-9658

A flaw has been found in O2OA up to 10.0-410. Impacted is an unknown function of the file /x_portal_assemble_designer/ja

3.5
CVE-2025-9657

A vulnerability was detected in O2OA up to 10.0-410. This issue affects some unknown processing of the file /x_program_c

3.5
CVE-2025-9655

A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /x_organization_assemble

3.5
CVE-2025-9653

A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona

3.5
CVE-2025-9652

A vulnerability was determined in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /intranet/

3.3
CVE-2025-9649

A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the f

3.5
CVE-2025-9646

A security flaw has been discovered in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_organ

3.7
CVE-2025-9604

A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backe

3.3
CVE-2025-43255

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sono

3.3
CVE-2024-44271

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record th

3.4
CVE-2025-48979

An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileg

2.4
CVE-2025-9591

A security vulnerability has been detected in ZrLog up to 3.1.5. This vulnerability affects unknown code of the file /ap

3.5
CVE-2025-9590

A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerabil

2.5
CVE-2025-9589

A vulnerability was determined in Cudy WR1200EA 2.3.7-20250113-121810. Affected is an unknown function of the file /etc/

2.5
CVE-2025-9577

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the f

2.5
CVE-2025-9576

A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/sha

2.4
CVE-2025-51643

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentic

3.7
CVE-2025-9514

A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registr

3.7
CVE-2025-9513

A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the fi

3.7
CVE-2025-55212

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-

3.5
CVE-2025-25733

Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829

3.1
CVE-2025-8447

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to an

2.4
CVE-2025-9430

A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/o

3.5
CVE-2025-9429

A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the fi

2.4
CVE-2025-9422

A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team

2.4
CVE-2025-9416

A security flaw has been discovered in oitcode samarium up to 0.9.6. This vulnerability affects unknown code of the file

3.8
CVE-2025-3456

On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in

3.5
CVE-2025-9407

A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file

2.4
CVE-2025-9404

A vulnerability was identified in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file /poin

3.3
CVE-2025-9403

A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of th

3.7
CVE-2025-9401

A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-f

3.3
CVE-2025-9396

A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal

3.3
CVE-2025-9389

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmov

3.5
CVE-2025-9388

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm.

3.3
CVE-2025-9384

A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /s

2.5
CVE-2025-9383

A security vulnerability has been detected in FNKvision Y215 CCTV Camera 10.194.120.40. This issue affects the function

1.6
CVE-2025-9381

A security flaw has been discovered in FNKvision Y215 CCTV Camera 10.194.120.40. This affects an unknown part of the fil

3.5
CVE-2025-55455

DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendte

2.7
CVE-2025-43759

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q

3.5
CVE-2025-55523

An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory tr

2.5
CVE-2025-9309

A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the c

3.3
CVE-2025-9308

A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/

3.5
CVE-2025-9306

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown

3.3
CVE-2025-9301

A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::Repla

3.8
CVE-2025-53971

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role mod

3.5
CVE-2025-49810

Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thre

3.5
CVE-2025-47700

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows

3.7
CVE-2025-9239

A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils

3.5
CVE-2025-9237

A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_

3.5
CVE-2025-9235

A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_event

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started