A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, co
RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may al
Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another
An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g
An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.
The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of
An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauth
Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker
Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowi
A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affe
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vulnerability that cou
A vulnerability has been found in PHPGurukul Rail Pass Management System 1.0 and classified as problematic. This vulnera
A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0.
A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this
A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is
Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by t
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 t
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through
Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, wi
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enum
In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic oper
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped in
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when ha
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be trigge
A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problemat
A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been classified as problematic. Affected is an unknown fun
A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing
A vulnerability, which was classified as problematic, was found in Konica Minolta bizhub up to 20250202. This affects an
A vulnerability, which was classified as problematic, was found in WuKongOpenSource WukongCRM 9.0. This affects an unkno
A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnera
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.
A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unk
A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability aff
SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on
A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an un
A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is s
A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affec
A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This af
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affe
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. A
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been classified as problematic.
A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This iss
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started