Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 90/162
3.5
CVE-2024-10754

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. This issue affects

3.5
CVE-2024-10753

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerabil

2.5
CVE-2024-10748

A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android.

3.5
CVE-2024-10747

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects

3.5
CVE-2024-10746

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unkno

3.5
CVE-2024-10745

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. Affected by this i

3.5
CVE-2024-10744

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. Affected by thi

3.5
CVE-2024-10743

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been classified as problematic. Affected is a

3.5
CVE-2024-10701

A vulnerability was found in PHPGurukul Car Rental Portal 1.0. It has been rated as problematic. This issue affects some

3.7
CVE-2024-7883

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floatin

3.7
CVE-2024-33623

A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially

3.5
CVE-2024-10503

A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some

3.8
CVE-2024-10228

The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified

2.2
CVE-2024-10452

Organization admins can delete pending invites created in an organization they are not part of.

2.7
CVE-2024-48921

Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can b

2.7
CVE-2024-41156

Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide po

2.4
CVE-2024-10479

A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknow

2.4
CVE-2024-10478

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affec

2.4
CVE-2024-10477

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknow

3.5
CVE-2024-30106

HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server err

2.4
CVE-2024-44265

The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.1, ma

2.4
CVE-2024-44251

This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker

3.3
CVE-2024-44222

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.1, ma

2.3
CVE-2024-44123

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequo

3.3
CVE-2024-40853

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18.

2.4
CVE-2024-40851

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 1

3.3
CVE-2024-40792

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app

3.3
CVE-2024-27849

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia

3.1
CVE-2024-49755

Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authenti

3.5
CVE-2024-10214

Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the

2.2
CVE-2024-8013

A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in express

2.2
CVE-2024-23843

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC

3.5
CVE-2024-10433

A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affecte

3.6
CVE-2024-50610

GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When

3.5
CVE-2024-10419

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected

2.4
CVE-2024-10414

A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an

3.5
CVE-2024-10412

A vulnerability was found in Poco-z Guns-Medical 1.0. It has been declared as problematic. Affected by this vulnerabilit

2.9
CVE-2024-47483

Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in a

3.5
CVE-2024-10348

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problemat

3.6
CVE-2023-50355

HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information t

3.5
CVE-2024-10276

A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability

3.7
CVE-2024-43173

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

3.3
CVE-2024-50057

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Free IRQ only if it was requested

3.3
CVE-2024-50044

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_

3.3
CVE-2024-47738

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't use rate mask for offchannel

2.4
CVE-2024-10199

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as problematic. Affected by

2.4
CVE-2024-10198

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as problematic. Affected

2.4
CVE-2024-10197

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. Affect

3.5
CVE-2024-10192

A vulnerability has been found in PHPGurukul IFSC Code Finder Project 1.0 and classified as problematic. This vulnerabil

3.5
CVE-2024-10191

A vulnerability, which was classified as problematic, was found in PHPGurukul Boat Booking System 1.0. This affects an u

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started