Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 76/162
3.5
CVE-2025-2700

A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown

3.5
CVE-2025-2699

A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue

3.5
CVE-2025-1203

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its

3.5
CVE-2025-1062

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its

3.5
CVE-2024-13124

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which coul

3.5
CVE-2024-10558

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could

3.5
CVE-2025-2673

A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an

3.5
CVE-2025-2650

A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. T

3.5
CVE-2025-2645

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. Affect

3.5
CVE-2025-2623

A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability

2.4
CVE-2025-2617

A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerabili

2.7
CVE-2025-1972

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici

2.4
CVE-2025-2616

A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown

2.4
CVE-2025-2590

A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic

3.3
CVE-2025-2588

A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the f

3.3
CVE-2025-27715

Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channe

3.5
CVE-2025-2583

A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown pa

3.5
CVE-2025-2582

A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unkn

3.5
CVE-2025-30345

An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user i

3.0
CVE-2025-30343

A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and

2.9
CVE-2025-2555

A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unkn

3.7
CVE-2025-29923

go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redi

3.1
CVE-2024-7598

A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enf

2.7
CVE-2024-13922

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins

3.5
CVE-2025-30259

The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protecti

2.7
CVE-2025-30258

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid bac

3.1
CVE-2025-30197

Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing t

2.6
CVE-2024-42176

HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous

3.5
CVE-2025-30235

Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed

3.3
CVE-2025-25040

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking

2.4
CVE-2025-2491

A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the

2.4
CVE-2025-2490

A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the functi

2.4
CVE-2025-2397

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 2

3.2
CVE-2025-29431

Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/departm

3.3
CVE-2025-25618

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and R

3.3
CVE-2025-1398

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker wit

3.7
CVE-2019-17659

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attack

3.5
CVE-2025-2377

A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by thi

3.5
CVE-2025-2375

A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management S

3.5
CVE-2025-2371

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as proble

2.4
CVE-2025-2366

A vulnerability, which was classified as problematic, was found in gougucms 4.08.18. This affects the function add of th

3.5
CVE-2025-2364

A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the fu

3.7
CVE-2025-2356

A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the funct

3.3
CVE-2025-2355

A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic. Affected by this issue is some

2.4
CVE-2025-2352

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects s

3.1
CVE-2025-2349

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as problematic. Affected by this vu

3.1
CVE-2025-2341

A vulnerability was found in IROAD Dash Cam X5 up to 20250203. It has been rated as problematic. This issue affects some

2.4
CVE-2025-2340

A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the

3.5
CVE-2025-1624

The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul

3.5
CVE-2025-1623

The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started