Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 59/162
3.7
CVE-2025-8742

A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unk

3.7
CVE-2025-8741

A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerab

2.4
CVE-2025-8740

A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0. It has been classified as problematic. Affected is an unkno

3.6
CVE-2025-55188

7-Zip before 25.01 does not always properly handle symbolic links during extraction.

3.5
CVE-2025-8737

A vulnerability, which was classified as problematic, was found in zlt2000 microservices-platform up to 6.0.0. This affe

3.3
CVE-2025-8735

A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the functi

3.3
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the f

3.4
CVE-2025-54940

An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerabilit

3.7
CVE-2025-54787

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vul

3.3
CVE-2025-8698

A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_ns

3.8
CVE-2025-48709

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta

3.7
CVE-2024-56339

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a re

2.5
CVE-2025-54798

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrar

3.2
CVE-2025-45764

jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who bel

3.5
CVE-2025-38746

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthor

3.7
CVE-2024-8244

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are

3.7
CVE-2025-8556

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to comprom

3.3
CVE-2025-21024

Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access se

3.3
CVE-2025-21023

Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sens

3.3
CVE-2025-21022

Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive i

3.3
CVE-2025-8586

A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_f

3.3
CVE-2025-8584

A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function

3.9
CVE-2025-44964

A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obta

3.5
CVE-2025-8555

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown funct

2.4
CVE-2025-8554

A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some

2.4
CVE-2025-8553

A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code

2.4
CVE-2025-8552

A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the

3.5
CVE-2025-8551

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some u

2.4
CVE-2025-8550

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerabilit

3.7
CVE-2025-8549

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function updat

3.7
CVE-2025-8548

A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function send

2.4
CVE-2025-8545

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue

2.4
CVE-2025-8544

A vulnerability classified as problematic was found in Portabilis i-Educar 2.10. Affected by this vulnerability is an un

2.4
CVE-2025-8543

A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. Affected is an unknown function of

2.4
CVE-2025-8542

A vulnerability was found in Portabilis i-Educar 2.10. It has been rated as problematic. This issue affects some unknown

2.4
CVE-2025-8541

A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. This vulnerability affects u

2.4
CVE-2025-8540

A vulnerability was found in Portabilis i-Educar 2.10. It has been classified as problematic. This affects an unknown pa

2.4
CVE-2025-8539

A vulnerability was found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this issue is some unkn

2.4
CVE-2025-8538

A vulnerability has been found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this vulnerability

3.7
CVE-2025-8537

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the fun

3.5
CVE-2025-8535

A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects

2.5
CVE-2025-8534

A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2pag

3.8
CVE-2025-46094

LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actions

3.7
CVE-2025-8528

A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of

2.4
CVE-2025-8521

A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.5. This issue affects som

2.7
CVE-2025-8519

A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of th

2.9
CVE-2025-50422

Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_f

3.1
CVE-2025-8515

A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1

3.2
CVE-2025-54956

The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header f

3.5
CVE-2025-8511

A vulnerability classified as problematic was found in Portabilis i-Diario 1.5.0. This vulnerability affects unknown cod

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started