Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 97/162
3.5
CVE-2024-7309

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This af

3.5
CVE-2024-7303

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as problematic. Thi

3.5
CVE-2024-7300

A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file

3.5
CVE-2024-7299

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issu

3.5
CVE-2024-7285

A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problemat

3.5
CVE-2024-7284

A vulnerability, which was classified as problematic, was found in SourceCodester Lot Reservation Management System 1.0.

3.1
CVE-2024-41945

fuels-ts is a library for interacting with Fuel v2. The typescript SDK has no awareness of to-be-spent transactions cau

3.5
CVE-2024-5250

In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations

3.7
CVE-2022-33167

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacke

3.5
CVE-2024-7225

A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This

1.9
CVE-2024-42155

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of protected- and secure-key

3.5
CVE-2024-7218

A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of t

2.6
CVE-2024-7216

A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832. It has been classified as problematic. This affects an unknow

3.3
CVE-2024-40832

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a con

2.4
CVE-2024-40822

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS

3.3
CVE-2024-40798

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.9 and iPadOS

3.3
CVE-2024-40795

This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14

3.3
CVE-2024-40778

An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.

2.4
CVE-2024-27862

A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown

3.3
CVE-2023-42957

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonom

3.3
CVE-2023-42949

This issue was addressed with improved data protection. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, wa

3.3
CVE-2023-42948

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may

3.3
CVE-2023-42925

The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17,

3.5
CVE-2024-6620

Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerabilit

3.3
CVE-2024-41027

In the Linux kernel, the following vulnerability has been resolved: Fix userfaultfd_api to return EINVAL as expected C

3.5
CVE-2024-7200

A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management Syst

3.5
CVE-2024-7170

A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unkno

3.5
CVE-2024-7163

A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file

3.5
CVE-2024-7162

A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. Affected by this issue is some

2.5
CVE-2024-7155

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this

2.8
CVE-2024-4786

An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application

3.3
CVE-2024-27358

An issue was discovered in WithSecure Elements Agent through 23.x for macOS and WithSecure Elements Client Security thro

3.3
CVE-2024-41686

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A l

2.2
CVE-2024-4811

In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restri

2.6
CVE-2024-7060

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior

2.7
CVE-2024-0231

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prio

2.4
CVE-2024-37533

IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to

3.5
CVE-2024-7068

A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects

3.5
CVE-2024-3454

An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK al

3.5
CVE-2024-41663

Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "

3.5
CVE-2024-41839

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou

3.5
CVE-2024-41829

In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

2.6
CVE-2024-41828

In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time

3.5
CVE-2024-41826

In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page

3.1
CVE-2024-32152

A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted maliciou

3.5
CVE-2024-6955

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affecte

3.5
CVE-2024-6954

A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. Affected

3.5
CVE-2024-6942

A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of t

3.5
CVE-2024-6941

A vulnerability, which was classified as problematic, has been found in ThinkSAAS 3.7.0. This issue affects some unknown

3.5
CVE-2024-6939

A vulnerability was found in Xinhu RockOA 2.6.3 and classified as problematic. Affected by this issue is the function ok

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started