A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulne
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed t
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricte
Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data exp
A vulnerability, which was classified as problematic, has been found in Legrand SMS PowerView 1.x. This issue affects so
A vulnerability classified as problematic was found in Legrand SMS PowerView 1.x. This vulnerability affects unknown cod
A vulnerability classified as problematic has been found in WCMS 11. This affects an unknown part of the file /index.php
A vulnerability was found in GFI KerioConnect 10.0.6. It has been declared as problematic. Affected by this vulnerabilit
A vulnerability was found in GFI KerioConnect 10.0.6. It has been classified as problematic. Affected is an unknown func
A vulnerability was found in GFI KerioConnect 10.0.6 and classified as problematic. This issue affects some unknown proc
A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability af
A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects
A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is t
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http
A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache
A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the functi
A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl
A vulnerability, which was classified as problematic, has been found in HDF5 up to 1.14.6. Affected by this issue is the
A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unk
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown
A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__a
A vulnerability classified as problematic has been found in HDF5 up to 1.14.6. This affects the function H5FS__sinfo_Sri
A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5
A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is t
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process
Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and e
A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerabi
A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allo
A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxEl
An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
Missing Authorization vulnerability in fatcatapps Quiz Cat quiz-cat allows Exploiting Incorrectly Configured Access Cont
In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Pyth
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or po
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior t
Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authent
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitr
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could
The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high pr
To exploit the vulnerability, it is necessary:
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi
The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could
The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, whic
A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unk
A vulnerability classified as problematic has been found in timschofield webERP up to 5.0.0.rc+13. This affects an unkno
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gate
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started