Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 96/162
3.3
CVE-2023-20513

An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtua

1.9
CVE-2023-20512

A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in in

3.9
CVE-2021-46772

Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to t

3.9
CVE-2021-26387

Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS

3.7
CVE-2022-45862

An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6

3.1
CVE-2024-41731

SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ne

3.7
CVE-2024-28166

SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the

3.5
CVE-2024-7686

A vulnerability, which was classified as problematic, was found in SourceCodester Kortex Lite Advocate Office Management

3.5
CVE-2024-7685

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Manag

3.5
CVE-2024-7684

A vulnerability classified as problematic was found in SourceCodester Kortex Lite Advocate Office Management System 1.0.

3.5
CVE-2024-7683

A vulnerability classified as problematic has been found in SourceCodester Kortex Lite Advocate Office Management System

3.5
CVE-2024-7678

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as problematic.

3.5
CVE-2024-7677

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problemati

3.5
CVE-2024-7660

A vulnerability has been found in SourceCodester File Manager App 1.0 and classified as problematic. Affected by this vu

3.7
CVE-2024-7659

A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function gen

3.5
CVE-2024-7657

A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the f

3.5
CVE-2024-7644

A vulnerability was found in SourceCodester Leads Manager Tool 1.0. It has been classified as problematic. This affects

3.3
CVE-2024-6692

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr

3.8
CVE-2024-5445

Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS cert

2.8
CVE-2024-43167

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer,

2.7
CVE-2024-22123

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file fo

3.0
CVE-2024-22122

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validat

3.3
CVE-2024-0102

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds

2.5
CVE-2024-42036

Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability

3.1
CVE-2024-6996

Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in speci

2.7
CVE-2024-7551

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown func

3.3
CVE-2024-7542

oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac

3.3
CVE-2024-7541

oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attack

3.3
CVE-2024-7540

oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac

3.9
CVE-2024-41811

ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain c

3.0
CVE-2024-42350

Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforc

3.8
CVE-2024-41960

mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a Ja

3.3
CVE-2024-40096

The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in

2.4
CVE-2024-7466

A vulnerability has been found in PMWeb 7.2.00 and classified as problematic. Affected by this vulnerability is an unkno

2.4
CVE-2024-7453

A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects u

3.5
CVE-2024-7368

A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vul

3.0
CVE-2024-41949

biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architec

3.0
CVE-2024-41948

biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architec

3.5
CVE-2024-7359

A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic.

2.7
CVE-2024-23600

Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a p

2.7
CVE-2024-41926

Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the co

3.8
CVE-2024-39837

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious r

2.7
CVE-2024-29977

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are

3.1
CVE-2024-38489

Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attack

3.5
CVE-2024-7343

A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknow

3.5
CVE-2024-7342

A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part

2.7
CVE-2022-4003

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a special

3.3
CVE-2024-37135

DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potential

3.3
CVE-2024-31203

A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer al

3.5
CVE-2024-7310

A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vuln

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started