A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 th
A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,
A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindow
A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allo
n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 st
Gibbon before 29.0.00 allows CSRF.
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the fun
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by th
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects th
A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information
A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as proble
A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platfor
A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the fun
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by th
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects th
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the funct
A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unk
A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some
A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability
A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown pa
A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issu
A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an u
A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the fil
In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small
In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).
In the memory_pages crate 0.1.0 for Rust, division by zero can occur.
In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.
In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.
The process_lock crate 0.1.0 for Rust allows data races in unlock.
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_Pars
A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a
TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in whi
Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer tha
GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3,
A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some u
Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single
A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown co
A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of
A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability i
A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. Thi
A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some
Failed login response could be different depending on whether the username was local or central.
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started