A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unkno
A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the funct
A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affec
A vulnerability classified as problematic was found in formtools.org Form Tools 3.1.1. This vulnerability affects unknow
A vulnerability classified as problematic has been found in formtools.org Form Tools 3.1.1. This affects an unknown part
A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unk
The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1.
A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affecte
HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an a
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloud
vodozemac is an open source implementation of Olm and Megolm in pure Rust. Versions before 0.7.0 of vodozemac use a non
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitiv
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104,
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This al
A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0 and classified as problemati
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 p
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23,
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are
An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted requ
In the Linux kernel, the following vulnerability has been resolved: drm/vc4: hdmi: Unregister codec device on unbind O
Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security
Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the applica
@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows a
Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capa
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 p
Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problema
TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App commun
Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerabil
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs
A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained
A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON re
A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 c
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, v
A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (A
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Phot
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Auto
Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary
Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch(
Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local atta
A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unkno
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Acad
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started