The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a l
A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as proble
A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown f
A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is th
Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast i
The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in a
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in th
A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pa
A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown fun
A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an un
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a Rem
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorizati
A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is a
NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthoriz
Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be
Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A bui
HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot
HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app ca
HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A maliciou
HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multipl
Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnera
A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as problematic. This iss
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mu
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud
A vulnerability classified as problematic was found in LabVantage LIMS 2017. Affected by this vulnerability is an unknow
A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the
A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown pro
A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unkno
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 p
When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message c
October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not
A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerab
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary
October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrator
DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institut
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai
Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were pre
Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high pri
udn News Android APP stores the unencrypted user session in the local database when user log into the application. A mal
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started