Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 63/162
3.8
CVE-2024-36349

A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a re

3.8
CVE-2024-36348

A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers specu

2.7
CVE-2025-24474

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiM

3.5
CVE-2025-42978

The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not re

2.7
CVE-2025-42954

SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a R

3.5
CVE-2025-7153

A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this

3.5
CVE-2025-7148

A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by

2.4
CVE-2025-7144

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vu

2.4
CVE-2025-7143

A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This

2.4
CVE-2025-7142

A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0.

2.4
CVE-2025-7141

A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this

2.4
CVE-2025-7140

A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is

2.4
CVE-2025-7139

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This iss

3.1
CVE-2025-20325

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1

3.5
CVE-2025-3777

Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image

3.5
CVE-2025-7113

A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown fu

3.5
CVE-2025-7112

A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown pr

3.5
CVE-2025-7111

A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects un

3.5
CVE-2025-7110

A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown pa

3.5
CVE-2025-7109

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issu

3.9
CVE-2025-53177

Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may

3.3
CVE-2025-53176

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil

3.7
CVE-2025-7095

A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an u

3.7
CVE-2025-7080

A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080

3.7
CVE-2025-7079

A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue aff

3.3
CVE-2025-7069

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link

3.3
CVE-2025-7068

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5F

3.3
CVE-2025-7067

A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_

2.7
CVE-2025-7061

A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerabilit

3.5
CVE-2025-7053

A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown pro

3.7
CVE-2025-49005

Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.

3.8
CVE-2025-6943

Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator

3.8
CVE-2025-6942

The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited duri

3.7
CVE-2025-53492

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F

2.0
CVE-2025-24335

Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, wh

3.3
CVE-2025-24334

The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release vers

3.1
CVE-2025-52463

Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerab

3.7
CVE-2025-4654

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au

3.3
CVE-2025-6952

A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the func

3.7
CVE-2025-6932

A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the functi

3.7
CVE-2025-6931

A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulne

2.8
CVE-2025-32462

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo

3.1
CVE-2025-52996

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ

3.4
CVE-2015-20112

RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption on a private network.

3.3
CVE-2025-6858

A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flus

3.3
CVE-2025-6857

A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the funct

3.3
CVE-2025-6856

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_li

3.5
CVE-2025-6849

A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknow

3.3
CVE-2025-6818

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_prot

3.3
CVE-2023-28903

An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started