A vulnerability, which was classified as problematic, has been found in code-projects Real Estate Property Management Sy
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability af
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via ex
Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initialization
Improper access control in the IOMMU may allow a privileged attacker to bypass RMP checks, potentially leading to a loss
An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resultin
Tungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability a
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-chec
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-chec
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Ac
Windows NTFS Elevation of Privilege Vulnerability
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attac
Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] i
A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_
The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the dat
SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied al
A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as problematic. This vuln
A vulnerability classified as problematic was found in code-projects Real Estate Property Management System 1.0. Affecte
A vulnerability classified as problematic has been found in code-projects Real Estate Property Management System 1.0. Af
A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affe
Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host heade
A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by
A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the fun
A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the f
A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdu
A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the func
OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to
A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup
A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function lin
A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the
A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the func
A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Maliciously constructed statements
Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML
A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerabilit
A vulnerability classified as problematic has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected is an unknown f
A vulnerability was found in Bharti Airtel Xstream Fiber up to 20250123. It has been rated as problematic. This issue af
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection t
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Emai
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacke
An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used fo
Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user
Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when th
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti
Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to ins
Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primiti
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started