Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the
IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parame
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI t
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal esc
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the renderi
In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.
NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit
A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issu
IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated
A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f9
Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing use
In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execu
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a gri
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col an
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing
In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expr
A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management
A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Manage
A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0.
A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as probl
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as pr
mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 88911
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,999999999999999
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later v
A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this iss
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an u
A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown fun
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim
An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64
A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown
A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is a
A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of t
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori
HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the
DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon c
DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory lea
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer un
Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all
The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape som
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started