Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 82/162
2.6
CVE-2025-0148

Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated us

3.9
CVE-2025-20643

In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo

3.5
CVE-2025-0972

A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part

3.5
CVE-2025-0971

A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been rated as problematic. Affected by this issue is

3.5
CVE-2025-0961

A vulnerability, which was classified as problematic, has been found in code-projects Job Recruitment 1.0. Affected by t

2.7
CVE-2024-53296

Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer Overflow vulnerability in th

3.1
CVE-2020-11936

gdbus setgid privilege escalation

3.3
CVE-2025-24336

SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may b

2.6
CVE-2023-6195

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16

3.9
CVE-2025-0146

Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to con

3.1
CVE-2025-0144

Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network

3.5
CVE-2025-0871

A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/a

3.5
CVE-2024-55416

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticate

2.4
CVE-2025-0800

A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown

3.3
CVE-2025-0797

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulne

3.5
CVE-2025-0795

A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the

3.5
CVE-2025-0794

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown funct

3.5
CVE-2025-0790

A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the f

3.5
CVE-2025-0787

A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an

3.5
CVE-2025-0785

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing o

3.7
CVE-2025-0784

A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability af

2.4
CVE-2024-11954

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func

3.3
CVE-2024-0149

NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files.

3.3
CVE-2025-24145

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and

3.3
CVE-2025-24141

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. A

3.3
CVE-2025-24121

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS

3.3
CVE-2025-24100

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3,

3.3
CVE-2024-54516

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma

3.3
CVE-2024-54475

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia

3.3
CVE-2024-44172

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia

3.7
CVE-2025-0730

A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected

3.5
CVE-2024-43446

An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even

3.8
CVE-2024-13116

The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow hig

2.4
CVE-2024-28766

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive inf

3.3
CVE-2025-0720

A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by th

3.8
CVE-2024-13450

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil

3.5
CVE-2025-0710

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unk

2.4
CVE-2025-0709

A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown pr

3.5
CVE-2025-0708

A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown

2.4
CVE-2025-0706

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problem

2.8
CVE-2024-35122

IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority r

3.2
CVE-2025-24034

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to

2.3
CVE-2024-52328

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker wi

3.3
CVE-2024-12079

ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow

2.8
CVE-2024-42186

BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handlin

2.5
CVE-2024-42185

BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This

2.5
CVE-2024-42184

BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operato

2.5
CVE-2024-42183

BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious ope

2.5
CVE-2024-42182

BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the appli

3.1
CVE-2025-0625

A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affect

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started