Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 79/162
2.4
CVE-2025-1879

A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some u

3.1
CVE-2025-1878

A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability a

3.7
CVE-2025-24023

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users

2.4
CVE-2025-1830

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown p

2.4
CVE-2025-0895

IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive i

2.0
CVE-2024-55907

IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno

2.4
CVE-2025-1817

A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown cod

3.5
CVE-2025-1807

A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknow

2.9
CVE-2025-27400

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun

3.8
CVE-2025-0914

An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users

3.3
CVE-2025-0759

IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared reso

3.3
CVE-2024-56812

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56811

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56810

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56496

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56495

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56494

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56493

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.9
CVE-2025-1693

The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database clu

2.7
CVE-2025-26698

Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, maliciou

2.7
CVE-2025-0760

A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials du

3.4
CVE-2025-22211

A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attacke

2.8
CVE-2024-53879

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a c

2.8
CVE-2024-53878

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a c

3.3
CVE-2024-53877

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause a NULL p

3.3
CVE-2024-53876

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-o

3.3
CVE-2024-53875

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-

3.3
CVE-2024-53874

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-

3.3
CVE-2024-53873

NVIDIA CUDA toolkit for Windows contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bou

3.3
CVE-2024-53872

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-

3.3
CVE-2024-53871

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-o

3.3
CVE-2024-53870

NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-

2.7
CVE-2025-27146

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains

3.8
CVE-2025-26977

Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorre

2.3
CVE-2024-51539

The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulner

3.5
CVE-2024-10545

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image

3.6
CVE-2025-27145

copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The

3.1
CVE-2025-26532

Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.

3.1
CVE-2025-26531

Insufficient capability checks made it possible to disable badges a user does not have permission to access.

3.4
CVE-2025-26528

The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

3.3
CVE-2025-1632

A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function li

3.1
CVE-2025-1412

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to

3.5
CVE-2025-1629

A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as probl

2.4
CVE-2025-1617

A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part

2.4
CVE-2025-1615

A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerabil

2.4
CVE-2025-1614

A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown

2.4
CVE-2025-1613

A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects

3.5
CVE-2025-1612

A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unk

3.5
CVE-2025-1597

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic.

2.4
CVE-2025-1592

A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affec

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started