Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 98/162
3.5
CVE-2024-6938

A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unkno

2.7
CVE-2024-6937

A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the funct

2.7
CVE-2024-6936

A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affec

2.4
CVE-2024-6935

A vulnerability classified as problematic was found in formtools.org Form Tools 3.1.1. This vulnerability affects unknow

2.4
CVE-2024-6934

A vulnerability classified as problematic has been found in formtools.org Form Tools 3.1.1. This affects an unknown part

3.5
CVE-2024-6932

A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unk

2.7
CVE-2024-6694

The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1.

3.5
CVE-2024-6907

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affecte

3.7
CVE-2024-30130

HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an a

3.9
CVE-2024-38806

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloud

2.9
CVE-2024-40640

vodozemac is an open source implementation of Olm and Megolm in pure Rust. Versions before 0.7.0 of vodozemac use a non

3.1
CVE-2023-42010

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitiv

3.5
CVE-2024-38870

Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104,

3.7
CVE-2024-30471

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This al

2.4
CVE-2024-6807

A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0 and classified as problemati

3.0
CVE-2024-6595

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 p

3.1
CVE-2024-21174

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23,

2.5
CVE-2024-21164

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

3.3
CVE-2024-21151

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a

3.7
CVE-2024-21144

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency

3.7
CVE-2024-21138

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

3.7
CVE-2024-21131

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

2.3
CVE-2024-21123

Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are

2.7
CVE-2024-40455

An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted requ

3.3
CVE-2022-48852

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: hdmi: Unregister codec device on unbind O

3.3
CVE-2024-6780

Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security

3.7
CVE-2024-40632

Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the applica

3.1
CVE-2024-39919

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an

2.6
CVE-2024-32945

Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows a

3.1
CVE-2023-41093

Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capa

3.8
CVE-2024-5470

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to

2.7
CVE-2024-2880

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 p

3.3
CVE-2024-23194

Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker

2.4
CVE-2024-6650

A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problema

3.7
CVE-2024-39886

TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App commun

3.1
CVE-2024-36452

Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerabil

2.9
CVE-2024-22018

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs

1.8
CVE-2024-22477

A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained

3.5
CVE-2024-21832

A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON re

3.1
CVE-2024-6501

A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 c

3.4
CVE-2024-26015

An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, v

3.3
CVE-2024-37996

A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (A

3.8
CVE-2024-37442

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Phot

2.7
CVE-2024-37253

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi

3.5
CVE-2024-35777

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Auto

3.3
CVE-2024-34692

Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary

2.0
CVE-2024-38372

Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch(

3.3
CVE-2024-34602

Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local atta

3.5
CVE-2024-6539

A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unkno

3.5
CVE-2024-37234

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Acad

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started