VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMa
EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by thei
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerab
A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.func
In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL.
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by th
nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate red
A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is a
A vulnerability, which was classified as problematic, was found in mirweiye Seven Bears Library CMS 2023. This affects a
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering
Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could poten
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing componen
Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration).
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The suppor
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are
The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be
A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unkn
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This aff
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This af
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark
A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerab
A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown
A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vul
A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor c
An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, m
Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtaine
CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacke
Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing us
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. T
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Fo
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker cou
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing
Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze sq
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficien
A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9
Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to cond
Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to ve
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortin
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started