A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as probl
A vulnerability, which was classified as problematic, has been found in Freeebird Hotel 酒店管理系统 API up to 1.2. Affected b
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue i
A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some
A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function un
A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function o
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bo
A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability i
A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by t
A vulnerability classified as problematic has been found in SourceCodester Online Student Clearance System 1.0. Affected
A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unkno
lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero.
dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not v
inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization.
A vulnerability classified as problematic has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown par
Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment w
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal
A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacke
JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL versio
Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows loc
Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers
Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buff
Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During We
Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Res
FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through buffer overflow.
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declar
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of th
A vulnerability has been found in MRCMS 3.1.2 and classified as problematic. This vulnerability affects unknown code of
A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file
A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unkn
A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functiona
A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknow
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the functi
A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an un
Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can b
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown pro
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion fa
A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is t
In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to inva
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started