The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the fail
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PA
A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as proble
Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect jf3-maintenance-mode.This i
A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue
A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u
A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects
A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. A
A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnera
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerab
A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set
A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This
A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic.
A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affe
A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown cod
A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use
spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom
In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix data leak in mmio_read() The mmio_rea
A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vu
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical acc
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical acc
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.
This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5,
Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentiall
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable
Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denia
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silen
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown c
A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is th
A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dan
A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown funct
The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the securit
An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. T
A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function u
A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is s
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could caus
Affected versions of Octopus Server had a weak content security policy.
An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF)
A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC R
Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started