Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili
Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili
Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili
Tungsten Automation Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili
Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili
Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The id
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an
Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain
A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the
A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOption
A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of
A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the f
A vulnerability was found in 115cms up to 20240807. It has been rated as problematic. Affected by this issue is some unk
A vulnerability was found in 115cms up to 20240807. It has been declared as problematic. Affected by this vulnerability
A vulnerability was found in 115cms up to 20240807. It has been classified as problematic. Affected is an unknown functi
A vulnerability was found in 115cms up to 20240807 and classified as problematic. This issue affects some unknown proces
In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that
Missing Authorization vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Exploiting Incorrectly Conf
The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, w
A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures local
A vulnerability, which was classified as problematic, has been found in code-projects Farmacia 1.0. This issue affects s
Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share li
user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that w
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly al
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is s
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected
Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unen
Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniquen
Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so
Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users th
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this
A vulnerability, which was classified as problematic, was found in code-projects Farmacia 1.0. Affected is an unknown fu
A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unk
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update dat
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions start
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functi
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnis
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb
Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated u
Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow a p
Out-of-bounds read for some OpenCL(TM) software may allow an authenticated user to potentially enable denial of service
Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to po
Out-of-bounds read in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially en
NULL pointer dereference in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentia
Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated us
Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before vers
A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown proces
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that we
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started