Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 94/162
2.3
CVE-2024-39582

Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacke

2.4
CVE-2024-45284

An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricte

2.7
CVE-2024-41728

Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logge

2.0
CVE-2024-44114

SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that r

3.5
CVE-2024-8610

A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affe

2.4
CVE-2024-8042

Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues wher

3.5
CVE-2024-8583

A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It ha

3.5
CVE-2024-8582

A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected

3.5
CVE-2024-8572

A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affect

3.5
CVE-2024-8571

A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as

3.5
CVE-2024-8563

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown

3.5
CVE-2024-8562

A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some u

3.3
CVE-2024-36137

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs

3.5
CVE-2024-8554

A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This is

2.6
CVE-2024-32771

An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP oper

3.5
CVE-2024-27125

A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could a

3.5
CVE-2024-6792

The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public p

3.7
CVE-2024-8462

A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of

3.7
CVE-2024-8460

A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue i

3.1
CVE-2024-45395

sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in version

3.1
CVE-2024-8417

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. Thi

3.6
CVE-2024-45314

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache d

3.5
CVE-2024-8411

A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_int

3.5
CVE-2024-8407

A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as p

2.4
CVE-2024-34649

Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attack

3.3
CVE-2024-34640

Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypa

3.9
CVE-2024-45620

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, w

3.9
CVE-2024-45618

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which woul

3.9
CVE-2024-45617

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted

3.9
CVE-2024-45616

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted

3.9
CVE-2024-45615

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initial

3.6
CVE-2024-45310

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as w

3.5
CVE-2024-43413

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr

2.5
CVE-2024-45305

gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to f

2.6
CVE-2023-7279

A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This

3.3
CVE-2024-28044

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.

3.5
CVE-2024-8370

A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the

3.5
CVE-2024-8367

A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a

3.3
CVE-2024-0109

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malfo

3.5
CVE-2024-44918

A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to exe

3.5
CVE-2024-8337

A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VC

3.7
CVE-2024-39300

Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function

2.0
CVE-2024-2502

An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occu

3.7
CVE-2024-43944

Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-com

3.8
CVE-2024-38304

Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of B

2.8
CVE-2024-45054

Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resource

3.5
CVE-2024-8209

A vulnerability was found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Aff

3.5
CVE-2024-8208

A vulnerability has been found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic

3.5
CVE-2024-42792

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.ph

3.5
CVE-2024-8172

A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. Th

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started