An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtua
A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in in
Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to t
Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ne
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the
A vulnerability, which was classified as problematic, was found in SourceCodester Kortex Lite Advocate Office Management
A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Manag
A vulnerability classified as problematic was found in SourceCodester Kortex Lite Advocate Office Management System 1.0.
A vulnerability classified as problematic has been found in SourceCodester Kortex Lite Advocate Office Management System
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as problematic.
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problemati
A vulnerability has been found in SourceCodester File Manager App 1.0 and classified as problematic. Affected by this vu
A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function gen
A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the f
A vulnerability was found in SourceCodester Leads Manager Tool 1.0. It has been classified as problematic. This affects
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr
Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS cert
DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer,
Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file fo
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validat
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds
Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability
Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in speci
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown func
oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac
oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attack
oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac
ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain c
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforc
mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a Ja
The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in
A vulnerability has been found in PMWeb 7.2.00 and classified as problematic. Affected by this vulnerability is an unkno
A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects u
A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vul
biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architec
biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architec
A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic.
Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a p
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the co
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious r
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are
Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attack
A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknow
A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part
A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a special
DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potential
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer al
A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vuln
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started