Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in th
XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to befo
XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4,
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to
snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerab
gosnowflake is the Snowflake Golang driver. Versions starting from 1.7.0 to before 1.13.3, are vulnerable to a Time-of-C
snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerabl
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, a
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Speci
A vulnerability was found in playeduxyz PlayEdu 开源培训系统 up to 1.8 and classified as problematic. This issue affects some
A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affe
The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.
The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of i
The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig
A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability
A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Aff
A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as problematic. Affected by this issue i
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vuln
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unkn
A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function Response
A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of
A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing
A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects
A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unkno
A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is a
In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), p
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft h
python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1>
A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some
Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for un
A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CS
A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log
Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c
In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started