A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been classified as problematic. This affects an
A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. This vulnerability
A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an unknow
A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been rated as problematic. Affected by this i
A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is a
Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and e
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase()
Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possessio
Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability all
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allow
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allow
Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported v
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24,
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are a
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported version
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are aff
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u421, 8
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulner
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects so
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file unde
SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in versio
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows a
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class,
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s
A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function send
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is a
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack**
A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as problematic. Affected by
A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some
A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnera
A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects s
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This
A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as probl
A vulnerability classified as problematic has been found in D-Link DSL-2750U R5B017. This affects an unknown part of the
An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vuln
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started