Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 86/162
2.2
CVE-2024-52589

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin

3.5
CVE-2024-12790

A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnera

3.3
CVE-2024-38864

Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (E

3.5
CVE-2024-12783

A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affect

3.7
CVE-2024-49820

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensiti

3.1
CVE-2024-42194

An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access

3.7
CVE-2024-9654

The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T

3.3
CVE-2024-54125

Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0

3.7
CVE-2024-12667

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unkn

3.5
CVE-2024-12665

A vulnerability, which was classified as problematic, was found in ruifang-tech Rebuild 3.8.5. Affected is an unknown fu

3.5
CVE-2024-12664

A vulnerability, which was classified as problematic, has been found in ruifang-tech Rebuild 3.8.5. This issue affects s

3.7
CVE-2024-12663

A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown

3.5
CVE-2024-56082

ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disab

3.5
CVE-2023-41695

Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Cont

3.5
CVE-2022-45819

Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control S

3.5
CVE-2021-32007

This issue affects: Secomea GateManager Version 9.5 and all prior versions. Protection Mechanism Failure vulnerability i

3.7
CVE-2024-12300

The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca

3.1
CVE-2024-10043

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting

3.3
CVE-2024-54493

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2. Privacy indicator

3.3
CVE-2024-54491

The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious application may be

2.4
CVE-2024-54485

The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macO

3.3
CVE-2024-44290

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18

3.3
CVE-2024-44200

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18

3.5
CVE-2024-12536

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Manag

2.4
CVE-2024-12503

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functi

3.7
CVE-2024-12483

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of t

3.1
CVE-2023-23472

IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain

3.4
CVE-2024-11053

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used f

2.5
CVE-2023-37395

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryptio

3.5
CVE-2024-52831

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou

3.5
CVE-2024-43755

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou

2.7
CVE-2024-55550 KEV

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local fi

3.1
CVE-2024-53245

In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low

2.7
CVE-2024-47577

Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability.

3.3
CVE-2024-47576

SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Win

2.7
CVE-2024-12174

An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged at

3.7
CVE-2023-28168

Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Con

3.5
CVE-2023-24375

Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedI

3.1
CVE-2023-23825

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control

3.8
CVE-2023-23814

Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured

3.1
CVE-2024-46901

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn

3.5
CVE-2024-12359

A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability

3.3
CVE-2024-12355

A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affecte

3.3
CVE-2024-12353

A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0.

3.5
CVE-2024-12348

A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is

3.5
CVE-2024-12346

A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unk

3.8
CVE-2024-6219

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust

3.8
CVE-2024-6156

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was prese

3.5
CVE-2024-12232

A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulner

3.1
CVE-2024-42195

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started