sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed
Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remo
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an inter
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release B
In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use
A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta
On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to
SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c
The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single fi
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al
The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard d
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowi
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan
A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th
A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the fil
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode o
A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality o
The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo
The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed
A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by th
The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read
A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of th
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy H
A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /soci
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When th
A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file
A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src
A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline
The root password hash of the device can be obtained through unencrypted information in the firmware.
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characte
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started