A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some u
A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability a
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users
A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown p
IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive i
IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno
A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown cod
A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknow
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users
IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared reso
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database clu
Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, maliciou
A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials du
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attacke
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a c
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a c
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause a NULL p
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-o
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-
NVIDIA CUDA toolkit for Windows contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bou
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-o
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains
Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorre
The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulner
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image
copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function li
Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to
A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as probl
A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part
A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerabil
A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown
A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects
A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unk
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic.
A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affec
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started