Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 88/162
3.3
CVE-2024-9757

Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

3.3
CVE-2024-9754

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

3.3
CVE-2024-9753

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

3.3
CVE-2024-9752

Tungsten Automation Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

3.3
CVE-2024-9749

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili

2.8
CVE-2024-52814

Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the

2.6
CVE-2024-45719

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The id

2.7
CVE-2024-52054

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an

3.5
CVE-2024-51337

Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain

3.5
CVE-2024-11588

A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the

3.5
CVE-2024-11587

A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOption

3.5
CVE-2024-11493

A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of

3.5
CVE-2024-11492

A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the f

3.5
CVE-2024-11491

A vulnerability was found in 115cms up to 20240807. It has been rated as problematic. Affected by this issue is some unk

3.5
CVE-2024-11490

A vulnerability was found in 115cms up to 20240807. It has been declared as problematic. Affected by this vulnerability

3.5
CVE-2024-11489

A vulnerability was found in 115cms up to 20240807. It has been classified as problematic. Affected is an unknown functi

3.5
CVE-2024-11488

A vulnerability was found in 115cms up to 20240807 and classified as problematic. This issue affects some unknown proces

3.5
CVE-2024-10515

In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that

2.7
CVE-2024-51671

Missing Authorization vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Exploiting Incorrectly Conf

3.8
CVE-2024-5030

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, w

3.4
CVE-2023-0657

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures local

3.5
CVE-2024-11259

A vulnerability, which was classified as problematic, has been found in code-projects Farmacia 1.0. This issue affects s

2.6
CVE-2024-52513

Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share li

3.3
CVE-2024-52512

user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that w

3.5
CVE-2024-52509

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly al

3.5
CVE-2024-52507

Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is s

2.4
CVE-2024-46383

Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected

1.8
CVE-2024-52525

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unen

2.6
CVE-2024-52521

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniquen

2.7
CVE-2024-52519

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so

3.0
CVE-2024-52516

Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users th

3.5
CVE-2024-11247

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this

3.5
CVE-2024-11246

A vulnerability, which was classified as problematic, was found in code-projects Farmacia 1.0. Affected is an unknown fu

3.5
CVE-2024-11240

A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unk

3.7
CVE-2024-42188

HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update dat

3.1
CVE-2024-9633

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions start

3.7
CVE-2024-11208

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functi

3.1
CVE-2024-10977

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnis

3.1
CVE-2024-45099

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb

3.8
CVE-2024-38660

Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated u

3.4
CVE-2024-33611

Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow a p

3.9
CVE-2024-32667

Out-of-bounds read for some OpenCL(TM) software may allow an authenticated user to potentially enable denial of service

3.9
CVE-2024-32485

Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to po

2.2
CVE-2024-28051

Out-of-bounds read in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially en

2.2
CVE-2024-28030

NULL pointer dereference in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentia

3.8
CVE-2024-25565

Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated us

3.4
CVE-2024-25563

Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before vers

3.5
CVE-2024-11175

A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown proces

3.7
CVE-2024-11168

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that we

2.3
CVE-2024-35274

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started