Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 91/162
3.5
CVE-2024-10155

A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been classified as problematic. This affects an

3.5
CVE-2024-10142

A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. This vulnerability

3.7
CVE-2024-10141

A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an unknow

2.7
CVE-2024-10128

A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been rated as problematic. Affected by this i

2.7
CVE-2024-10122

A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is a

3.8
CVE-2024-46897

Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and e

3.1
CVE-2024-38820

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() 

3.3
CVE-2023-6728

Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possessio

3.5
CVE-2024-47836

Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability all

2.4
CVE-2024-4692

Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allow

2.4
CVE-2024-4211

Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allow

3.0
CVE-2024-21257

Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported v

2.3
CVE-2024-21253

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

3.1
CVE-2024-21251

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24,

3.8
CVE-2024-21247

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a

2.2
CVE-2024-21244

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are a

2.2
CVE-2024-21243

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are a

3.5
CVE-2024-21242

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19

2.2
CVE-2024-21237

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported version

2.2
CVE-2024-21232

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions

3.1
CVE-2024-21231

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are aff

3.7
CVE-2024-21217

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

3.7
CVE-2024-21211

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

3.7
CVE-2024-21210

Vulnerability in Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u421, 8

2.0
CVE-2024-21209

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a

3.7
CVE-2024-21208

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

3.7
CVE-2024-9506

Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulner

2.4
CVE-2024-9952

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects so

2.5
CVE-2024-30117

A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file unde

2.0
CVE-2024-48909

SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in versio

3.5
CVE-2024-47826

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows a

3.7
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class,

3.1
CVE-2024-6762

Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s

3.7
CVE-2024-9907

A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function send

3.5
CVE-2024-9906

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is a

3.7
CVE-2024-45403

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3

3.1
CVE-2024-25622

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers

2.4
CVE-2024-9856

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this

3.7
CVE-2024-47869

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack**

3.5
CVE-2024-9810

A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as problematic. Affected by

2.4
CVE-2024-9807

A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some

3.5
CVE-2024-9806

A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnera

3.5
CVE-2024-9805

A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects s

3.5
CVE-2024-9803

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This

3.5
CVE-2024-9799

A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as probl

2.4
CVE-2024-9792

A vulnerability classified as problematic has been found in D-Link DSL-2750U R5B017. This affects an unknown part of the

3.7
CVE-2024-9596

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to

2.7
CVE-2024-45149

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v

2.7
CVE-2024-45135

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v

2.7
CVE-2024-45134

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vuln

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started