A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. This affects the function Gerar of
A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some u
A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerabilit
A vulnerability was found in Portabilis i-Educar 2.9. It has been classified as problematic. Affected is an unknown func
A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problema
A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authenti
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics whi
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may cause an exposure of sensitive sys
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level infor
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelbla
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is
A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish
Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified
A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control d
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.
A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability
A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerabili
CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers
CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers
A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low p
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Conta
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman se
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
A security flaw has been discovered in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. This affects an unknown part of the file /gr
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa
The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby deny
The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.
The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.
The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: N
A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_de
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the functi
A vulnerability, which was classified as problematic, has been found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c
A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is t
A vulnerability, which was classified as problematic, was found in Comodo Dragon up to 134.0.6998.179. This affects an u
A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by
A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerabilit
A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown f
A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by
JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipst
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started