Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 84/162
2.6
CVE-2024-42175

HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and the

3.7
CVE-2024-42174

HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration o

3.4
CVE-2025-23113

An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while perfo

3.8
CVE-2024-13308

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Bac

3.1
CVE-2024-13293

Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects

3.5
CVE-2024-13261

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affect

3.7
CVE-2025-22151

Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type conf

3.7
CVE-2024-10106

A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's

3.5
CVE-2025-0348

A vulnerability was found in CampCodes DepEd Equipment Inventory System 1.0. It has been rated as problematic. This issu

3.5
CVE-2025-0342

A vulnerability, which was classified as problematic, was found in CampCodes Computer Laboratory Management System 1.0.

3.8
CVE-2025-22449

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to

3.5
CVE-2025-22445

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regardin

3.5
CVE-2025-0339

A vulnerability classified as problematic has been found in code-projects Online Bike Rental 1.0. Affected is an unknown

3.5
CVE-2024-13213

A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of

2.4
CVE-2024-13209

A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function o

2.4
CVE-2024-13205

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue

2.4
CVE-2024-13202

A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the functi

3.6
CVE-2024-37372

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignor

3.5
CVE-2024-13199

A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability i

3.7
CVE-2024-13198

A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown func

3.5
CVE-2024-13197

A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been rated as problematic. This issue affects the

3.5
CVE-2024-13196

A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been declared as problematic. This vulnerability

3.5
CVE-2024-13192

A vulnerability, which was classified as problematic, was found in ZeroWdd myblog 1.0. Affected is the function update o

3.4
CVE-2024-54010

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an un

3.5
CVE-2025-0301

A vulnerability, which was classified as problematic, has been found in code-projects Online Book Shop 1.0. Affected by

3.3
CVE-2025-0245

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been b

3.7
CVE-2021-20455

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive

3.5
CVE-2025-0295

A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic. Affected by this issue is

3.3
CVE-2024-12425

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation

2.7
CVE-2024-10562

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could

2.7
CVE-2024-10102

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some

3.1
CVE-2024-10527

The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mo

2.7
CVE-2024-48455

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi

3.3
CVE-2024-55626

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr

3.1
CVE-2024-51472

IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vuln

3.9
CVE-2024-12970

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILG

2.4
CVE-2024-13143

A vulnerability was found in ZeroWdd studentmanager 1.0. It has been rated as problematic. This issue affects the functi

2.4
CVE-2024-13142

A vulnerability was found in ZeroWdd studentmanager 1.0. It has been declared as problematic. This vulnerability affects

2.4
CVE-2025-0228

A vulnerability has been found in code-projects Local Storage Todo App 1.0 and classified as problematic. This vulnerabi

3.5
CVE-2024-13141

A vulnerability classified as problematic was found in osuuu LightPicture up to 1.2.2. This vulnerability affects unknow

2.4
CVE-2025-0220

A vulnerability, which was classified as problematic, was found in Trimble SPS851 488.01. This affects an unknown part o

3.5
CVE-2024-13140

A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.3. Affected is an unknown function of th

2.4
CVE-2024-13137

A vulnerability was found in wangl1989 mysiteforme 1.0. It has been classified as problematic. This affects the function

3.5
CVE-2024-13135

A vulnerability has been found in Emlog Pro 2.4.3 and classified as problematic. Affected by this vulnerability is an un

2.4
CVE-2025-0219

A vulnerability, which was classified as problematic, has been found in Trimble SPS851 488.01. Affected by this issue is

3.5
CVE-2024-13132

A vulnerability classified as problematic was found in Emlog Pro up to 2.4.3. This vulnerability affects unknown code of

3.8
CVE-2024-56321

GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the

3.5
CVE-2025-0175

A vulnerability was found in code-projects Online Shop 1.0. It has been declared as problematic. This vulnerability affe

3.5
CVE-2024-13083

A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. Affected is an unknown fu

3.5
CVE-2024-13082

A vulnerability was found in PHPGurukul Land Record System 1.0. It has been rated as problematic. This issue affects som

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started