Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacke
An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricte
Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logge
SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that r
A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affe
Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues wher
A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It ha
A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected
A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affect
A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as
A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown
A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some u
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs
A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This is
An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP oper
A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could a
The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public p
A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of
A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue i
sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in version
A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. Thi
Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache d
A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_int
A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as p
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attack
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypa
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, w
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which woul
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initial
runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as w
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr
gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to f
A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.
A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the
A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a
NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malfo
A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to exe
A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VC
Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function
An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occu
Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-com
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of B
Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resource
A vulnerability was found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Aff
A vulnerability has been found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.ph
A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. Th
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started