Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 74/162
2.3
CVE-2024-32122

A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7

2.7
CVE-2025-3403

A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101. It has been

3.5
CVE-2025-3393

A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been cla

3.5
CVE-2025-3392

A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue

3.5
CVE-2025-3391

A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this v

3.5
CVE-2025-3390

A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the

3.5
CVE-2025-3389

A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue

3.5
CVE-2025-3387

A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknow

2.4
CVE-2025-3386

A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some un

2.4
CVE-2025-3385

A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability

3.2
CVE-2025-29087

In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the en

2.7
CVE-2025-27686

Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an

3.7
CVE-2025-3360

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp

3.3
CVE-2025-27534

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

3.3
CVE-2025-25057

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

3.3
CVE-2025-24304

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds write.

3.3
CVE-2025-22842

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.3
CVE-2025-22452

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.3
CVE-2025-20102

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.1
CVE-2025-3329

A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affect

3.5
CVE-2025-3327

A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown proc

3.5
CVE-2025-3326

A vulnerability has been found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This vulnerability affects unkn

3.5
CVE-2025-3297

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is a

3.5
CVE-2025-3253

A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown proc

3.5
CVE-2025-3252

A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unkn

3.5
CVE-2025-3251

A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part

3.5
CVE-2025-3219

A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown

3.5
CVE-2024-42208

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in

3.3
CVE-2025-3198

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability i

3.3
CVE-2025-32054

In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file

3.3
CVE-2025-3160

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerabili

2.4
CVE-2025-3157

A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. It has been rated as problematic. This issue affects som

3.5
CVE-2025-3152

A vulnerability classified as problematic has been found in caipeichao ThinkOX 1.0. This affects an unknown part of the

2.4
CVE-2025-3149

A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been classified as problemati

3.3
CVE-2025-3148

A vulnerability was found in codeprojects Product Management System 1.0 and classified as problematic. This issue affect

3.3
CVE-2025-3145

A vulnerability, which was classified as problematic, has been found in MindSpore 2.5.0. Affected by this issue is the f

3.3
CVE-2025-3144

A vulnerability classified as problematic was found in MindSpore 2.5.0. Affected by this vulnerability is the function m

3.3
CVE-2025-3136

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function t

2.2
CVE-2025-29991

Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It u

3.1
CVE-2025-3122

A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the fu

3.3
CVE-2025-3121

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module

3.5
CVE-2024-42325

Zabbix API user.get returns all users that share common group with the calling user. This includes media and other infor

3.1
CVE-2024-36469

Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.

3.1
CVE-2025-3082

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different o

2.4
CVE-2025-30469

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person wi

2.4
CVE-2025-24193

This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with

2.7
CVE-2024-40864

The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequ

2.4
CVE-2025-3036

A vulnerability, which was classified as problematic, was found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b

3.3
CVE-2025-3010

A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this i

3.5
CVE-2025-3005

A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is s

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started