Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 9/162
3.3
CVE-2026-17072

A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC

3.3
CVE-2026-55977

Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio

2.7
CVE-2026-14821

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting out

3.5
CVE-2026-14819

The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputtin

2.4
CVE-2026-64745

This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, m

2.4
CVE-2026-10683

In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handl

3.5
CVE-2026-48051

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy

3.3
CVE-2026-17513

A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file

3.5
CVE-2026-56538

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi

3.5
CVE-2026-56537

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar

3.3
CVE-2026-17512

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the fi

1.8
CVE-2026-40000

The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compre

3.8
CVE-2026-14189

The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them

3.3
CVE-2026-66011

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid optio

3.1
CVE-2026-17039

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based autho

3.8
CVE-2026-12690

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions,

2.4
CVE-2026-15687

A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new

3.5
CVE-2026-64800

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

3.7
CVE-2026-52686

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat

3.7
CVE-2026-52684

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data

3.1
CVE-2026-55708

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unboun

3.7
CVE-2026-54478

In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with

3.7
CVE-2026-50243

In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of

3.7
CVE-2026-46582

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be

3.7
CVE-2026-44687

In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate l

3.7
CVE-2026-42955

In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost do

3.7
CVE-2026-41637

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted

3.3
CVE-2026-44187

A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with

2.9
CVE-2026-16517

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function i

3.1
CVE-2026-16417

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the ren

3.1
CVE-2026-62508

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

1.9
CVE-2026-61303

Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported

2.2
CVE-2026-61214

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th

2.8
CVE-2026-61187

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The

3.7
CVE-2026-61104

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking

2.9
CVE-2026-61096

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported

2.7
CVE-2026-61081

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Suppo

3.3
CVE-2026-61071

Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineerin

3.1
CVE-2026-61048

Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supp

1.9
CVE-2026-61047

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).

3.8
CVE-2026-61036

Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported ver

1.9
CVE-2026-61028

Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). S

3.7
CVE-2026-61015

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

2.2
CVE-2026-60950

Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Support

3.1
CVE-2026-60939

Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp

3.1
CVE-2026-60937

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup

3.1
CVE-2026-60936

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup

3.1
CVE-2026-60930

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

3.1
CVE-2026-60929

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

3.1
CVE-2026-60922

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Suppo

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started