Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 92/162
2.7
CVE-2024-45133

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vuln

3.1
CVE-2024-45120

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use

3.5
CVE-2024-30118

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in

2.9
CVE-2024-47813

Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s int

2.9
CVE-2024-39586

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high

3.7
CVE-2023-36325

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) v

2.5
CVE-2024-27457

Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a p

3.1
CVE-2024-47780

TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree wit

3.5
CVE-2024-47951

In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

3.5
CVE-2024-47950

In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

3.3
CVE-2024-33506

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7

3.3
CVE-2024-8518

CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a s

3.3
CVE-2024-45476

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualizat

3.3
CVE-2024-34671

Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows l

3.3
CVE-2024-9026

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configu

3.1
CVE-2024-8925

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data

3.3
CVE-2024-45382

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

3.3
CVE-2024-43697

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.

3.3
CVE-2024-43696

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

3.9
CVE-2024-47814

Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (vi

3.7
CVE-2024-9554

A vulnerability classified as problematic was found in Sovell Smart Canteen System up to 3.0.7303.30513. Affected by thi

3.9
CVE-2024-41511

A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allo

3.7
CVE-2024-9513

A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this is

3.3
CVE-2024-0125

NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can ca

3.3
CVE-2024-0124

NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can ca

3.3
CVE-2024-0123

NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker m

3.3
CVE-2024-24122

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an att

3.5
CVE-2024-47612

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifica

3.5
CVE-2024-47526

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulne

3.5
CVE-2024-9411

A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admi

3.7
CVE-2024-30132

HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to o

2.7
CVE-2024-28808

An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenti

3.3
CVE-2024-28811

An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute a

2.4
CVE-2024-42496

Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vu

3.5
CVE-2024-9323

A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affect

3.5
CVE-2024-9320

A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerabil

3.5
CVE-2024-9299

A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This a

3.5
CVE-2024-9291

A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75

3.0
CVE-2024-45744

TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can r

3.3
CVE-2024-9283

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown functi

2.4
CVE-2024-9279

A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown

3.5
CVE-2024-9277

A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unkno

3.5
CVE-2024-9276

A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of

2.6
CVE-2024-8974

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4

3.1
CVE-2024-4099

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to

2.5
CVE-2024-9203

A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows.

3.1
CVE-2024-47145

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels

3.1
CVE-2024-47003

Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a str

3.1
CVE-2024-45843

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denyli

3.3
CVE-2023-25189

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web E

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started