Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 66/162
3.7
CVE-2025-6052

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, co

2.5
CVE-2025-48825

RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may al

2.7
CVE-2024-38823

Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.

2.7
CVE-2024-38822

Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another

3.5
CVE-2025-4227

An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g

3.7
CVE-2025-5982

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.

3.1
CVE-2025-49198

The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of

2.8
CVE-2025-1699

An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauth

2.8
CVE-2025-1698

Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker

3.1
CVE-2025-4128

Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowi

3.5
CVE-2025-5984

A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affe

3.5
CVE-2025-47096

Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vulnerability that cou

3.5
CVE-2025-5976

A vulnerability has been found in PHPGurukul Rail Pass Management System 1.0 and classified as problematic. This vulnera

3.5
CVE-2025-5974

A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0.

2.4
CVE-2025-5973

A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this

2.4
CVE-2025-5972

A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is

2.7
CVE-2025-36576

Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high

2.4
CVE-2025-5970

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by t

3.1
CVE-2025-22251

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 t

3.2
CVE-2023-29184

An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through

3.0
CVE-2025-42990

Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, wi

3.7
CVE-2025-42988

Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enum

3.2
CVE-2025-0036

In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic oper

3.9
CVE-2025-5918

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped in

2.8
CVE-2025-5917

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when ha

3.9
CVE-2025-5916

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be trigge

3.1
CVE-2025-5889

A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problemat

3.5
CVE-2025-5887

A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been classified as problematic. Affected is an unknown fun

3.5
CVE-2025-5886

A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing

3.5
CVE-2025-5884

A vulnerability, which was classified as problematic, was found in Konica Minolta bizhub up to 20250202. This affects an

3.5
CVE-2025-5879

A vulnerability, which was classified as problematic, was found in WuKongOpenSource WukongCRM 9.0. This affects an unkno

3.7
CVE-2025-5864

A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnera

3.3
CVE-2025-27563

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

3.3
CVE-2025-27242

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

3.3
CVE-2025-26693

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

3.3
CVE-2025-25217

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

3.3
CVE-2025-23235

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.3
CVE-2025-21082

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

3.3
CVE-2025-20063

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

3.5
CVE-2025-5797

A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unk

3.5
CVE-2025-5796

A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability aff

3.7
CVE-2025-49011

SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on

3.5
CVE-2025-5765

A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an un

3.5
CVE-2025-5764

A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is s

3.5
CVE-2025-5757

A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affec

2.4
CVE-2025-5727

A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This af

2.4
CVE-2025-5726

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affe

2.4
CVE-2025-5725

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. A

2.4
CVE-2025-5724

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been classified as problematic.

2.4
CVE-2025-5723

A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This iss

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started