Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rende
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the ren
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the ren
A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlR
A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndD
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metag
The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-re
The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown fu
Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allow
The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as pa
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug
The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin
A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This imp
A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /a
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could
A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMo
The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd
The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does
The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Bui
A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou
A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce
Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They
A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability i
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc
A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of th
Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/blue
The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp
FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started