A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC
Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting out
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputtin
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, m
In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handl
Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy
A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar
A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the fi
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compre
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid optio
A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based autho
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions,
A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat
If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unboun
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with
In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be
In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate l
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost do
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function i
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the ren
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Suppo
Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineerin
Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supp
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported ver
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Suppo
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started