A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unk
A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerab
A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0. It has been classified as problematic. Affected is an unkno
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
A vulnerability, which was classified as problematic, was found in zlt2000 microservices-platform up to 6.0.0. This affe
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the functi
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the f
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerabilit
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vul
A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_ns
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a re
tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrar
jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who bel
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthor
The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to comprom
Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access se
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sens
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive i
A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_f
A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obta
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown funct
A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some
A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code
A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the
A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some u
A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerabilit
A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function updat
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function send
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue
A vulnerability classified as problematic was found in Portabilis i-Educar 2.10. Affected by this vulnerability is an un
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. Affected is an unknown function of
A vulnerability was found in Portabilis i-Educar 2.10. It has been rated as problematic. This issue affects some unknown
A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. This vulnerability affects u
A vulnerability was found in Portabilis i-Educar 2.10. It has been classified as problematic. This affects an unknown pa
A vulnerability was found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this issue is some unkn
A vulnerability has been found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this vulnerability
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the fun
A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2pag
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actions
A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of
A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.5. This issue affects som
A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of th
Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_f
A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header f
A vulnerability classified as problematic was found in Portabilis i-Diario 1.5.0. This vulnerability affects unknown cod
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started