A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects som
Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al
A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Af
A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Co
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive inf
A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the compon
on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0
A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unk
A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of
Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2
Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.
Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a
Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are
Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The suppo
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0
A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vu
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problem
A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerab
A vulnerability classified as problematic was found in Sapido RB-1802 1.0.32. This vulnerability affects unknown code of
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like f
A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the functi
A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR o
A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects t
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole in
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the
A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosu
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint
A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerabi
Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs git
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that cou
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that cou
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this
A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is
A vulnerability has been found in 9fans plan9port up to 9da5b44 and classified as problematic. Affected by this vulnerab
A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that c
External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a networ
Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started