The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul
A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknow
A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and ac
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A succe
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiW
Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Sn
An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from
An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 pr
In the Linux kernel, the following vulnerability has been resolved: mm/zswap: fix inconsistency when zswap_store_page()
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentic
A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown func
A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown proces
A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been declared as problematic. This vulnerability
A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an
A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is s
A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulne
A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unkn
A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue aff
PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows r
A vulnerability classified as problematic was found in aitangbao springboot-manager 3.0. This vulnerability affects unkn
A vulnerability classified as problematic has been found in aitangbao springboot-manager 3.0. This affects an unknown pa
An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.
A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the fun
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file
A vulnerability, which was classified as problematic, has been found in Claro A7600-A1 RNR4-A72T-2x16_v2110403_CLA_32_16
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDC
In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immu
The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperl
The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin thr
The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certai
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with
SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to es
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due
A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 1
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitiv
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sectio
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the functi
A vulnerability classified as problematic was found in ftcms 2.1. Affected by this vulnerability is an unknown functiona
A vulnerability was found in dayrui XunRuiCMS up to 4.6.3. It has been rated as problematic. This issue affects some unk
A vulnerability was found in OpenXE up to 1.12. It has been declared as problematic. This vulnerability affects unknown
A vulnerability, which was classified as problematic, was found in Control iD RH iD 25.2.25.0. This affects an unknown p
A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is t
A vulnerability classified as problematic was found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected by this v
A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as problematic. This issue
A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been declared as problematic. This vu
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started