Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 78/162
3.5
CVE-2025-1363

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise an

3.7
CVE-2025-2114

A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Bus

3.2
CVE-2025-27839

operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet

3.1
CVE-2025-2093

A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affec

3.5
CVE-2025-2087

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects s

3.5
CVE-2025-2086

A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown co

3.5
CVE-2025-2085

A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of

3.5
CVE-2025-2084

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as p

3.5
CVE-2025-2049

A vulnerability classified as problematic has been found in code-projects Blood Bank System 1.0. Affected is an unknown

3.5
CVE-2025-2047

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This a

3.5
CVE-2025-2032

A vulnerability classified as problematic was found in ChestnutCMS 1.5.2. This vulnerability affects the function rename

2.4
CVE-2024-13902

A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown

3.1
CVE-2025-1540

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 p

2.5
CVE-2024-11035

Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a ty

2.7
CVE-2025-22212

A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticate

3.5
CVE-2025-1967

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0.

3.5
CVE-2025-1957

A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u

3.5
CVE-2025-1955

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic

2.6
CVE-2025-1953

A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an

3.9
CVE-2025-1939

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could h

3.5
CVE-2024-47259

Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a

3.5
CVE-2025-1905

A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This a

3.5
CVE-2025-1904

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by

3.8
CVE-2025-24309

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o

3.8
CVE-2025-24301

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u

3.8
CVE-2025-23420

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o

3.3
CVE-2025-23418

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.8
CVE-2025-23414

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u

3.8
CVE-2025-23409

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u

3.8
CVE-2025-23240

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o

3.3
CVE-2025-23234

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

3.3
CVE-2025-22897

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

3.3
CVE-2025-22847

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.3
CVE-2025-22841

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.3
CVE-2025-22837

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

3.8
CVE-2025-22835

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o

3.3
CVE-2025-22443

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.3
CVE-2025-21097

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

3.3
CVE-2025-21089

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.8
CVE-2025-21084

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through t

3.8
CVE-2025-20626

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u

3.8
CVE-2025-20091

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u

3.8
CVE-2025-20081

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u

3.8
CVE-2025-20024

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through i

3.3
CVE-2025-20021

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

3.3
CVE-2025-20011

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

3.8
CVE-2025-0587

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through i

2.4
CVE-2025-1892

A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of t

3.2
CVE-2025-27221

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage

2.0
CVE-2025-1880

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an u

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started