Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other gr
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a par
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
The course upload preview contained an XSS risk for users uploading unsafe data.
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Teli
A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS
Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-
Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker contro
A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of
Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID
A vulnerability classified as problematic was found in dstar2018 Agency up to 61. Affected by this vulnerability is an u
Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VP
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 1
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions start
A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknow
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as proble
A vulnerability was found in Campcodes Simple Student Information System 1.0. It has been declared as problematic. This
A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for se
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not
A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the funct
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for ot
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enro
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowi
A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing o
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits tha
Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a lo
Missing Authorization in GitHub repository hamza417/inure prior to Build95.
JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Pr
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vuln
FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to
In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to s
In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissio
In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, du
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbi
A vulnerability classified as problematic was found in AlexanderLivanov FotosCMS2 up to 2.4.3. This vulnerability affect
A vulnerability classified as problematic was found in hu60t hu60wap6. Affected by this vulnerability is the function ma
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, int
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lea
In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused depu
In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started