Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated us
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo
A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part
A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been rated as problematic. Affected by this issue is
A vulnerability, which was classified as problematic, has been found in code-projects Job Recruitment 1.0. Affected by t
Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer Overflow vulnerability in th
gdbus setgid privilege escalation
SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may b
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16
Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to con
Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network
A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/a
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticate
A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulne
A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the
A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown funct
A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the f
A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an
A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing o
A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability af
A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func
NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files.
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. A
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3,
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even
The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow hig
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive inf
A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by th
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil
A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unk
A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown pr
A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown
A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problem
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority r
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker wi
ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow
BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handlin
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This
BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operato
BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious ope
BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the appli
A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affect
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started