A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a re
A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers specu
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiM
The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not re
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a R
A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this
A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by
A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vu
A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0.
A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this
A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This iss
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1
Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image
A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown fu
A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown pr
A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects un
A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown pa
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issu
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil
A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an u
A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080
A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue aff
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5F
A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_
A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerabilit
A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown pro
Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator
The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited duri
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, wh
The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release vers
Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerab
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au
A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the func
A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the functi
A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulne
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption on a private network.
A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flus
A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the funct
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_li
A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknow
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_prot
An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started