Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 87/162
3.6
CVE-2024-54014

Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skyla

3.5
CVE-2024-12183

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS

3.5
CVE-2024-12182

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some

3.5
CVE-2024-12181

A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown fun

3.5
CVE-2024-12180

A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file

3.7
CVE-2024-38829

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from

3.5
CVE-2024-54158

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

3.7
CVE-2024-54155

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import wit

3.1
CVE-2024-54153

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query par

3.8
CVE-2024-53502

Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.

2.8
CVE-2024-53921

An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders

2.0
CVE-2024-49417

Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch

2.4
CVE-2024-49414

Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to t

2.2
CVE-2024-53564

A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) fil

3.7
CVE-2024-11856

A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.

3.5
CVE-2024-12001

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is an unknown func

3.5
CVE-2024-12000

A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects s

3.5
CVE-2024-11997

A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown

3.5
CVE-2024-11996

A vulnerability was found in code-projects Farmacia 1.0 and classified as problematic. Affected by this issue is some un

3.5
CVE-2024-11995

A vulnerability has been found in code-projects Farmacia 1.0 and classified as problematic. Affected by this vulnerabili

2.2
CVE-2024-53861

pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting

3.1
CVE-2024-53701

Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications

3.5
CVE-2024-11971

A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerab

3.5
CVE-2024-49503

A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE mana

3.5
CVE-2024-49502

A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup

1.9
CVE-2024-53855

Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management wit

2.7
CVE-2024-36464

When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type

2.7
CVE-2024-42333

The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read

3.7
CVE-2024-42332

The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with addit

3.3
CVE-2024-42331

In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript

3.3
CVE-2024-42329

The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function

3.3
CVE-2024-42328

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allo

3.0
CVE-2024-36468

The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix s

3.5
CVE-2024-11820

A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This is

3.5
CVE-2024-11742

A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management Syst

2.2
CVE-2024-22117

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the s

3.8
CVE-2024-8160

Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficie

3.5
CVE-2024-11678

A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnera

3.5
CVE-2024-11677

A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affec

3.5
CVE-2024-11676

A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this is

3.5
CVE-2024-11675

A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by th

2.7
CVE-2024-10492

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file th

3.5
CVE-2024-11660

A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown

3.5
CVE-2024-7056

The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high p

3.5
CVE-2024-10710

The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow hig

3.3
CVE-2024-9763

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

3.3
CVE-2024-9762

Tungsten Automation Power PDF OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabil

3.3
CVE-2024-9761

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

3.3
CVE-2024-9760

Tungsten Automation Power PDF PNG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

3.3
CVE-2024-9759

Tungsten Automation Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started