Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff
A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. This affects an un
A vulnerability was found in Facile Sistemas Cloud Apps up to 20250107. It has been classified as problematic. Affected
A vulnerability has been found in Union Bank of India Vyom 8.0.34 on Android and classified as problematic. This vulnera
A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. Affected is
A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This i
A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected
A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0.
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an att
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability af
Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an au
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&s
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.
An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_IN
In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially le
A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been classified as problematic. Affected is an unknown
A vulnerability has been found in Fanli2012 native-php-cms 1.0 and classified as problematic. This vulnerability affects
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker
OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with inval
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear link ID from bitmap during li
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfi
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlock
Windows Smart Card Reader Information Disclosure Vulnerability
A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by t
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix S
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix S
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6
A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.1
A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versio
An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSAS
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may a
An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 thr
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specificati
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQ
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unkno
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmit
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, incl
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Micr
A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is
A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown functio
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started