Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 62/162
3.5
CVE-2025-7786

A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects som

2.2
CVE-2025-6227

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al

3.5
CVE-2025-7767

A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Af

3.5
CVE-2025-2818

A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Co

3.5
CVE-2024-42209

HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive inf

3.5
CVE-2025-7748

A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the compon

3.4
CVE-2025-7339

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0

3.5
CVE-2025-7729

A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unk

3.5
CVE-2025-7728

A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of

2.4
CVE-2025-53840

Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2

3.1
CVE-2025-7703

Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.

2.4
CVE-2025-52687

Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point

2.3
CVE-2025-53029

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

2.7
CVE-2025-50104

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte

2.2
CVE-2025-50100

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that

2.7
CVE-2025-50098

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

3.1
CVE-2025-50081

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a

2.7
CVE-2025-50066

Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are

3.7
CVE-2025-50065

Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version

3.7
CVE-2025-30752

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The suppo

2.4
CVE-2025-30750

Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-1

3.7
CVE-2025-53019

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.

3.7
CVE-2025-53014

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0

3.5
CVE-2025-7601

A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vu

3.7
CVE-2025-7577

A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problem

3.5
CVE-2025-7569

A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerab

2.4
CVE-2025-7554

A vulnerability classified as problematic was found in Sapido RB-1802 1.0.32. This vulnerability affects unknown code of

3.7
CVE-2025-1220

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like f

3.3
CVE-2025-7485

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the functi

3.7
CVE-2025-7464

A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR o

3.7
CVE-2025-7453

A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects t

3.7
CVE-2025-51591

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole in

3.5
CVE-2025-53862

A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw

3.1
CVE-2025-53861

A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the

3.5
CVE-2025-7435

A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It

3.5
CVE-2025-49462

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosu

3.4
CVE-2025-27889

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint

3.5
CVE-2025-7408

A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerabi

3.6
CVE-2025-27613

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs git

2.7
CVE-2025-6168

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that cou

2.7
CVE-2025-4972

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that cou

3.5
CVE-2023-50458

In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

1.6
CVE-2025-7215

A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this

1.6
CVE-2025-7214

A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is

3.3
CVE-2025-7209

A vulnerability has been found in 9fans plan9port up to 9da5b44 and classified as problematic. Affected by this vulnerab

3.3
CVE-2025-7207

A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope

2.4
CVE-2025-49546

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that c

3.5
CVE-2025-49760

External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a networ

3.3
CVE-2025-49756

Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a

3.1
CVE-2025-49731

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started