Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 6/162
2.0
CVE-2026-48791

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed

3.7
CVE-2026-73425

Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remo

3.3
CVE-2026-18096

IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial

3.1
CVE-2026-11937

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

3.3
CVE-2025-9486

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2

3.0
CVE-2026-18246

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an inter

3.1
CVE-2026-65926

An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release B

3.0
CVE-2026-49262

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is

3.8
CVE-2026-70467

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM

3.7
CVE-2026-18044

The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use

3.5
CVE-2026-64951

A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic

2.5
CVE-2026-73283

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar

3.5
CVE-2026-73281

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi

2.7
CVE-2026-48412

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att

3.3
CVE-2026-73071

Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta

3.6
CVE-2026-11985

On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to

3.7
CVE-2026-66774

SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this

3.8
CVE-2026-58245

SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th

3.7
CVE-2026-58239

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send

3.7
CVE-2026-44762

SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c

2.5
CVE-2026-11812

The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single fi

3.7
CVE-2026-11811

The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS

3.9
CVE-2026-19411

A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al

3.7
CVE-2026-11809

The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z

3.3
CVE-2026-21062

Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard d

3.7
CVE-2026-17016

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun

3.8
CVE-2026-14211

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl

2.2
CVE-2026-12971

The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowi

2.3
CVE-2026-19382

A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan

2.3
CVE-2026-19380

A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the

3.7
CVE-2026-12372

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th

3.3
CVE-2026-19368

A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the fil

3.7
CVE-2026-19361

A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode o

3.1
CVE-2026-19352

A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality o

3.8
CVE-2026-17011

The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo

2.7
CVE-2026-16957

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed

3.3
CVE-2026-19324

A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by th

3.6
CVE-2026-11742

The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read

3.3
CVE-2026-19245

A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of th

3.7
CVE-2026-71849

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy H

3.5
CVE-2026-19230

A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /soci

2.5
CVE-2026-17435

File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When th

3.5
CVE-2026-19209

A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file

3.7
CVE-2026-19208

A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src

2.4
CVE-2026-19207

A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some

2.3
CVE-2026-61477

An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline

2.4
CVE-2026-49005

The root password hash of the device can be obtained through unencrypted information in the firmware.

3.3
CVE-2026-64652

GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characte

3.7
CVE-2026-48082

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

2.7
CVE-2026-48074

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started