Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin
A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnera
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (E
A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affect
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensiti
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T
Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unkn
A vulnerability, which was classified as problematic, was found in ruifang-tech Rebuild 3.8.5. Affected is an unknown fu
A vulnerability, which was classified as problematic, has been found in ruifang-tech Rebuild 3.8.5. This issue affects s
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown
ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disab
Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Cont
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control S
This issue affects: Secomea GateManager Version 9.5 and all prior versions. Protection Mechanism Failure vulnerability i
The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2. Privacy indicator
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious application may be
The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18
A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Manag
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functi
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of t
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used f
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryptio
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local fi
In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability.
SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Win
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged at
Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Con
Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedI
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn
A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability
A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affecte
A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0.
A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is
A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unk
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust
Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was prese
A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulner
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started