Several months back I did a talk on “From LOW to PWNED” at hashdays and BSides Atlanta. The point of the talk was to show some examples were medium and low vulnerabilities have led to a further exploitation or impact that I would consider “high” or above. Clients should pay attention to low/medium vulns as much as they do high+ vulns, pentesters/VA people/security teams should also pay attention. Tools/scanner are great for automating tasks but I don’t think we are there yet with the technology of taking multiple less severe vulnerabilities and turning them into something significant.”]
Source: https://blog.carnal0wnage.com/2012/04/from-low-to-pwned-0-intro.html

